CVE-2009-4314: Medium severity oracle sun ray software vulnerability
Sun Ray Server Software 4.1 on Solaris 10, when Automatic Multi-Group Hotdesking (AMGH) is enabled, responds to a logout action by immediately logging the user in again, which makes it easier for physically proximate attackers to obtain access to a session by going to an unattended DTU device.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4314?
CVE-2009-4314 has been rated as a medium severity vulnerability due to the risk of unauthorized access.
How do I fix CVE-2009-4314?
To remediate CVE-2009-4314, disable the Automatic Multi-Group Hotdesking feature on Sun Ray Server Software 4.1.
Which products are affected by CVE-2009-4314?
CVE-2009-4314 affects Sun Ray Server Software 4.1 running on Solaris 10.
What kind of attack does CVE-2009-4314 facilitate?
CVE-2009-4314 facilitates session hijacking by allowing physically proximate attackers to access unattended sessions.
Is there a patch available for CVE-2009-4314?
There is no specific patch for CVE-2009-4314; disabling the vulnerable feature is the recommended action.