Vulnerability Description
Sun Ray Server Software (SRSS) 1.3 and 2.0 for Solaris 2.6, 7 and 8 does not properly detect a smartcard removal when the card is quickly removed, reinserted, and removed again, which could cause a user session to stay logged in and allow local users to gain unauthorized access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun | Ray Server Software | 1.3 |
References
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F53922
- http://www.kb.cert.org/vuls/id/100780US Government Resource
- http://www.securityfocus.com/bid/7457PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11905
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F53922
- http://www.kb.cert.org/vuls/id/100780US Government Resource
- http://www.securityfocus.com/bid/7457PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11905
FAQ
What is CVE-2004-0701?
CVE-2004-0701 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Sun Ray Server Software (SRSS) 1.3 and 2.0 for Solaris 2.6, 7 and 8 does not properly detect a smartcard removal when the card is quickly removed, reinserted, and removed again, which could cause a us...
How severe is CVE-2004-0701?
CVE-2004-0701 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0701?
Check the references section above for vendor advisories and patch information. Affected products include: Sun Ray Server Software.