Vulnerability Details CVE-2009-2856
Sun Virtual Desktop Infrastructure (VDI) 3.0, when anonymous binding is enabled, does not properly handle a client's attempt to establish an authenticated and encrypted connection, which might allow remote attackers to read cleartext VDI configuration-data requests by sniffing LDAP sessions on the network.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 42.8%
CVSS Severity
CVSS v2 Score 3.5
Products affected by CVE-2009-2856
-
cpe:2.3:a:sun:virtual_desktop_infrastructure:3.0
-
cpe:2.3:o:sun:solaris:10.0