CVE-2009-3923

VirtualBox <2.0.8-2.0.10 - Info Disclosure

Title source: llm
STIX 2.1

Description

The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/54136
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-66-268328-1
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/36917

Scores

EPSS 0.0062
EPSS Percentile 70.4%

Details

CWE
CWE-287
Status published
Products (3)
sun/virtual_desktop_infrastructure 3.0
sun/virtualbox 2.0.8
sun/virtualbox 2.0.10
Published Nov 10, 2009
Tracked Since Feb 18, 2026