First published: Mon Apr 28 2008(Updated: )
Sun Java System Directory Proxy Server 6.0, 6.1, and 6.2 classifies a connection using the "bind-dn" criteria, which can cause an incorrect application of policy and allows remote attackers to bypass intended access restrictions for the server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun ONE Directory Server | =6.0 | |
Sun ONE Directory Server | =6.1 | |
Sun ONE Directory Server | =6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1995 is classified as a medium severity vulnerability that allows remote attackers to bypass intended access restrictions.
To mitigate CVE-2008-1995, apply the latest patches provided by Sun for the Java System Directory Proxy Server.
CVE-2008-1995 affects Sun Java System Directory Proxy Server versions 6.0, 6.1, and 6.2.
CVE-2008-1995 enables remote attackers to bypass access restrictions through incorrect application of policy based on bind-dn criteria.
As of now, implementing strict access policies and monitoring connections may help reduce risks associated with CVE-2008-1995.