HIGH🇬🇧 English

CVE-2007-0882

CVSS 10.0v2.0pub. 2007-02-12upd. 2026-04-23

Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.

oryginał EN
CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
  • Oracle Solaris

    OS
    Oracle
    1011
  • Sun Sunos

    OS
    Sun
    5.105.11
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2020-14871CRITICAL10.0⚠ KEVPL ✓ten sam produkt

Oracle Solaris PAM — zdalne przejęcie systemu bez uwierzytelnienia

CVE-2013-2251CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Apache Struts 2: RCE przez prefiks action/redirect w parametrach

CVE-2026-46978CRITICAL10.0PL ✓ten sam produkt

Auth Bypass w Oracle Solaris Remote Administration Daemon (CVSS 10.0)

CVE-2025-36038CRITICAL9.0PL ✓ten sam produkt

RCE w IBM WebSphere Application Server przez niebezpieczną deserializację

CVE-2021-39085CRITICAL9.8PL ✓ten sam produkt

SQL Injection w IBM Sterling B2B Integrator — nieautoryzowany dostęp do bazy danych