CVE-2008-1995: High severity sun one directory server vulnerability
Sun Java System Directory Proxy Server 6.0, 6.1, and 6.2 classifies a connection using the "bind-dn" criteria, which can cause an incorrect application of policy and allows remote attackers to bypass intended access restrictions for the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1995?
CVE-2008-1995 is classified as a medium severity vulnerability that allows remote attackers to bypass intended access restrictions.
How do I fix CVE-2008-1995?
To mitigate CVE-2008-1995, apply the latest patches provided by Sun for the Java System Directory Proxy Server.
What versions are affected by CVE-2008-1995?
CVE-2008-1995 affects Sun Java System Directory Proxy Server versions 6.0, 6.1, and 6.2.
What type of attack does CVE-2008-1995 enable?
CVE-2008-1995 enables remote attackers to bypass access restrictions through incorrect application of policy based on bind-dn criteria.
Is there a workaround for CVE-2008-1995?
As of now, implementing strict access policies and monitoring connections may help reduce risks associated with CVE-2008-1995.