First published: Tue Dec 31 2002(Updated: )
Sun Ray Server Software (SRSS) 1.3, when Non-Smartcard Mobility (NSCM) is enabled, allows remote attackers to login as another user by running dtlogin from a system that supports the XDMCP client.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Sun Ray Software | =1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2036 is considered a high severity vulnerability due to the potential for remote attackers to gain unauthorized access to user accounts.
To fix CVE-2002-2036, disable Non-Smartcard Mobility (NSCM) in the Sun Ray Server Software configuration.
CVE-2002-2036 affects installations of Sun Ray Server Software version 1.3 when NSCM is enabled.
CVE-2002-2036 allows remote attackers to impersonate other users by exploiting the dtlogin via an XDMCP client.
CVE-2002-2036 was reported in the year 2002, highlighting long-standing vulnerability issues in the Sun Ray Server Software.