>> Sun Integrated Lights-Out Manager Denial of Service Vulnerability
Title : Sun Integrated Lights-Out Manager Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2008-2890 CVE ID : CVE-2008-4722
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-10-22
Technical Description
A vulnerability has been identified in Sun Integrated Lights-Out Manager, which could be exploited by attackers to cause a denial of service, or by malicious users to bypass security restrictions. This issue is caused by an error in the web interface, which could allow attackers to gain unauthorized access to the service processor (SP) and power off or reset the system, creating a denial of service condition.
On Sun servers and Sun Blades, this vulnerability could be exploited by unprivileged users who have access to the ILOM web interface to gain unauthorized access to the host operating system.