CVE-2009-4440: Race Condition
Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly handle multiple client connections within a short time window, which allows remote attackers to hijack the backend connection of an authenticated user, and obtain the privileges of this user, by making a client connection in opportunistic circumstances, related to "long binds," aka Bug Ids 6828462 and 6823593.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4440?
CVE-2009-4440 is classified as a medium severity vulnerability due to the potential for remote attackers to hijack backend connections.
How do I fix CVE-2009-4440?
To fix CVE-2009-4440, upgrade to a patched version of Sun Java System Directory Server above 6.3.1.
What systems are affected by CVE-2009-4440?
CVE-2009-4440 affects Sun Java System Directory Server versions 6.0 through 6.3.1.
What type of attack does CVE-2009-4440 allow?
CVE-2009-4440 allows remote attackers to hijack backend connections of authenticated users.
Is there a workaround for CVE-2009-4440?
Currently, there are no known workarounds for CVE-2009-4440 other than upgrading to a secure version.