CVE-2003-1563: Medium severity Sun Solaris vulnerability

Published Dec 31, 2003
·
Updated

Sun Cluster 2.2 through 3.2 for Oracle Parallel Server / Real Application Clusters (OPS/RAC) allows local users to cause a denial of service (cluster node panic or abort) by launching a daemon listening on a TCP port that would otherwise be used by the Distributed Lock Manager (DLM), possibly involving this daemon responding in a manner that spoofs a cluster reconfiguration.

Affected Software

21 affected components
Sun Solaris=2.6
Sun Solaris=7
Sun SunOS=5.8
Sun Cluster=2.2
Sun SunOS=5.9
Sun SunOS=5.10
Sun Cluster=3.0
Sun Cluster=3.1
Sun Cluster=3.2
All of the following
Any of the following
Sun Solaris=2.6
Sun Solaris=7
Sun SunOS=5.8
Sun Cluster=2.2
All of the following
Any of the following
Sun SunOS=5.8
Sun SunOS=5.9
Sun SunOS=5.10
Any of the following
Sun Cluster=3.0
Sun Cluster=3.1
All of the following
Any of the following
Sun SunOS=5.9
Sun SunOS=5.10
Sun Cluster=3.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Identify the TCP port(s) used by the Distributed Lock Manager (DLM) in your Sun Cluster configuration, and prevent unauthorized local daemons from interfering with them. Implement host-based controls such as firewall/iptables/nftables rules to block connections to the DLM port(s) from non-cluster or untrusted addresses, and implement process allowlisting or OS RBAC so that only the Sun Cluster/cluster system processes (and authorised administrators) can start services that bind to those DLM port(s).

  2. Operational

    Audit each cluster node for unauthorized daemons listening on the DLM TCP port(s). Locate listening processes (for example by examining netstat/lsof output), stop/terminate any unauthorized daemons, remove or disable the user-installed daemon, and review local user accounts and privileges to prevent reinstallation or relaunch.

Event History

Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
05:00 AM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Aug 18, 2008
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2003-1563?

CVE-2003-1563 is classified as a denial of service vulnerability impacting Sun Cluster versions 2.2 to 3.2.

2

How do I fix CVE-2003-1563?

To mitigate CVE-2003-1563, ensure that TCP ports used by the Distributed Lock Manager are not occupied by unauthorized daemons.

3

What versions are affected by CVE-2003-1563?

CVE-2003-1563 affects Sun Cluster versions 2.2, 3.0, 3.1, and 3.2.

4

Can local users exploit CVE-2003-1563?

Yes, local users can exploit CVE-2003-1563 to cause a cluster node panic or abort.

5

What system does CVE-2003-1563 impact?

CVE-2003-1563 specifically impacts Sun Cluster used in Oracle Parallel Server and Real Application Clusters environments.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203