Denial of Service Vulnerability in Sun Java System Directory Server
CVE-2009-4441

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
28 December 2009

Summary

The Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition versions 6.0 through 6.3.1 lacks the SO_KEEPALIVE socket option. This oversight allows remote attackers to exploit multiple connections to exhaust available connection slots, resulting in a denial-of-service condition. This vulnerability emphasizes the importance of proper socket configuration to ensure the availability of server resources.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.