First published: Mon Feb 12 2001(Updated: )
The clustmon service in Sun Cluster 2.x does not require authentication, which allows remote attackers to obtain sensitive information such as system logs and cluster configurations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Cluster | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0077 is considered to have a high severity due to the lack of authentication in the clustmon service, allowing remote attackers to access sensitive information.
To fix CVE-2001-0077, you should implement authentication mechanisms for the clustmon service or upgrade to a version of Sun Cluster that addresses this vulnerability.
CVE-2001-0077 can expose sensitive information such as system logs and cluster configurations.
Sun Cluster 2.0 is specifically affected by CVE-2001-0077.
A practical workaround for CVE-2001-0077 is to restrict network access to the clustmon service until proper authentication is configured.