Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pwc8-mq5g-v7jf

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly handle multiple client connections within a short time window, which allows remote attackers to hijack the backend connection of an authenticated user, and obtain the privileges of this user, by making a client connection in opportunistic circumstances, related to "long binds," aka Bug Ids 6828462 and 6823593.

Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly handle multiple client connections within a short time window, which allows remote attackers to hijack the backend connection of an authenticated user, and obtain the privileges of this user, by making a client connection in opportunistic circumstances, related to "long binds," aka Bug Ids 6828462 and 6823593.

EPSS

Процентиль: 78%
0.01144
Низкий

Дефекты

CWE-362

Связанные уязвимости

nvd
около 16 лет назад

Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly handle multiple client connections within a short time window, which allows remote attackers to hijack the backend connection of an authenticated user, and obtain the privileges of this user, by making a client connection in opportunistic circumstances, related to "long binds," aka Bug Ids 6828462 and 6823593.

EPSS

Процентиль: 78%
0.01144
Низкий

Дефекты

CWE-362