Lucene search

K
cveMitreCVE-2008-5099
HistoryNov 17, 2008 - 6:18 p.m.

CVE-2008-5099

2008-11-1718:18:47
CWE-200
mitre
web.nvd.nist.gov
24
cve-2008-5099
sun
ldoms manager
obp
security password
cleartext
vulnerability
sparc firmware
local users

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

28.0%

Sun Logical Domain Manager (aka LDoms Manager or ldm) 1.0 through 1.0.3 displays the value of the OpenBoot PROM (OBP) security-password variable in cleartext, which allows local users to bypass the SPARC firmware’s password protection, and gain privileges or obtain data access, via the “ldm ls -l” command, a different vulnerability than CVE-2008-4992.

Affected configurations

Nvd
Node
sunlogical_domain_managerMatch1.0_nil_sparc
OR
sunlogical_domain_managerMatch1.0.1_nil_sparc
OR
sunlogical_domain_managerMatch1.0.2_nil_sparc
OR
sunlogical_domain_managerMatch1.0.3_nil_sparc
VendorProductVersionCPE
sunlogical_domain_manager1.0cpe:2.3:a:sun:logical_domain_manager:1.0:_nil_:sparc:*:*:*:*:*
sunlogical_domain_manager1.0.1cpe:2.3:a:sun:logical_domain_manager:1.0.1:_nil_:sparc:*:*:*:*:*
sunlogical_domain_manager1.0.2cpe:2.3:a:sun:logical_domain_manager:1.0.2:_nil_:sparc:*:*:*:*:*
sunlogical_domain_manager1.0.3cpe:2.3:a:sun:logical_domain_manager:1.0.3:_nil_:sparc:*:*:*:*:*

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

28.0%

Related for CVE-2008-5099