CVE-2008-4722
Last modified
CVE-2008-4722 is a vulnerability of currently unknown severity. Unspecified vulnerability in Sun Integrated Lights-Out Manager (ILOM) 2.0.1.5 through 2.0.4.26 allows remote authenticated users to (1) access the service processor (SP) and cause a denial of service (shutdown or reboot), or (2) access the host operating system and have an unspecified impact, via unknown vectors.. EPSS estimates a 1.97% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in Sun Integrated Lights-Out Manager (ILOM) 2.0.1.5 through 2.0.4.26 allows remote authenticated users to (1) access the service processor (SP) and cause a denial of service (shutdown or reboot), or (2) access the host operating system and have an unspecified impact, via unknown vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Sun | Integrated Lights-Out Manager | All versions | — |
| Sun | Blade 6000 Modular System With Chassis | <= 2.0 | — |
| Sun | Blade 6048 Modular System With Chassis | <= 2.0 | — |
| Sun | Blade 8000 Modular System | <= 2.1.1 | — |
| Sun | Blade 8000p Modular System | <= 2.1.1 | — |
| Sun | Blade T6320 Server Module | <= 7.1.6 | — |
| Sun | Blade X6220 With Server Module Software | <= 2.0 | — |
| Sun | Blade X6250 With Server Module Software | <= 2.0 | — |
| Sun | Blade X6450 With Server Module Software | <= 2.0 | — |
| Sun | Blade X8400 | <= 2.0.2 | — |
| Sun | Blade X8420 | <= 2.0.2 | — |
| Sun | Blade X8440 | <= 2.0.2 | — |
| Sun | Blade X8450 | <= 2.1 | — |
| Sun | Fire X2250 Server | <= sw_1.1 | — |
| Sun | Fire X4100 Server | <= sw_1.5.1 | — |
| Sun | Fire X4100m2 Server | <= sw_2.1 | — |
| Sun | Fire X4140 Server | <= sw_2.1 | — |
| Sun | Fire X4150 Server | <= sw_2.0 | — |
| Sun | Fire X4200 Server | <= sw_1.5.1 | — |
| Sun | Fire X4200m2 Server | <= sw_2.1 | — |
| Sun | Fire X4240 Server | <= sw_2.1 | — |
| Sun | Fire X4250 Server | <= sw_1.1 | — |
| Sun | Fire X4440 Server | <= sw_2.1 | — |
| Sun | Fire X4450 Server | <= sw_2.1.0 | — |
| Sun | Fire X4500 Server | <= sw_1.5 | — |
| Sun | Fire X4540 Server | <= sw_1.0 | — |
| Sun | Fire X4600 Server | <= sw_1.4 | — |
| Sun | Fire X4600m2 Server | <= sw_2.1.2 | — |
| Sun | Netra | <= cp3260_atca_blade_server | 7.1.6 |
| Sun | Netra | <= t5220_server | 7.1.6 |
| Sun | Netra | <= t5440_server | 7.1.4a |
| Sun | Netra X4200m2 Server | <= sw_2.1 | — |
| Sun | Netra X4250 Server | <= sw_1.1 | — |
| Sun | Netra X4450 | <= sw_1.1 | — |
| Sun | Sparc Enterprise Server T5120 | <= 7.1.6 | — |
| Sun | Sparc Enterprise Server T5140 | <= 7.1.6 | — |
| Sun | Sparc Enterprise Server T5220 | <= 7.1.6 | — |
| Sun | Sparc Enterprise Server T5240 | <= 7.1.6 | — |
| Sun | Sparc Enterprise Server T5440 | <= 7.1.5b | — |
References
- http://secunia.com/advisories/32298Vendor Advisory
- http://secunia.com/advisories/32298Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-4722?
How severe is CVE-2008-4722?
How do I fix CVE-2008-4722?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-4716SQL injection vulnerability in show.php in BitmixSoft PHP-La…
- CVE-2008-4717SQL injection vulnerability in bannerclick.php in ZEELYRICS …
- CVE-2008-4718Directory traversal vulnerability in help/mini.php in X7 Cha…
- CVE-2008-4719PHP remote file inclusion vulnerability in cms/classes/opene…
- CVE-2008-4720Multiple PHP remote file inclusion vulnerabilities in The Ge…
- CVE-2008-4721PHP Jabbers Post Comment 3.0 allows remote attackers to bypa…
- CVE-2008-4723Multiple cross-site scripting (XSS) vulnerabilities in Mozil…
- CVE-2008-4724Multiple cross-site scripting (XSS) vulnerabilities in Googl…
- CVE-2008-4725Cross-site scripting (XSS) vulnerability in Opera.dll in Ope…
- CVE-2008-4726Stack-based buffer overflow in the SFTP subsystem in GoodTec…
- CVE-2008-4727Cross-site scripting (XSS) vulnerability in the contact upda…
- CVE-2008-4728Multiple insecure method vulnerabilities in the DeployRun.De…
Are you affected by CVE-2008-4722?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
