CVE-2009-4314: Sun Ray Server Software 4.1 on Solaris 10, when Automatic Multi-Group Hotdesking (AMGH) is enabled, responds to a logout
infovulnerability
security
Summary
Sun Ray Server Software 4.1 on Solaris 10 has a vulnerability where enabling Automatic Multi-Group Hotdesking (AMGH, a feature that automatically logs users back in after logout) causes users to be immediately logged in again after logging out. This makes it easier for an attacker who is physically near an unattended device to gain access to someone else's session.
Solution / Mitigation
Patches are available at http://sunsolve.sun.com/search/document.do?assetkey=1-21-139548-03-1 and http://sunsolve.sun.com/search/document.do?assetkey=1-66-268228-1.
Vulnerability Details
CVSS Score
4.4
EPSS (30-day exploit probability)
EPSS: 0.1%
Classification
Attack SophisticationTrivial
Taxonomy References
CWE (Weakness Type)
Original source: https://nvd.nist.gov/vuln/detail/CVE-2009-4314
First tracked: February 15, 2026 at 08:46 PM
Classified by LLM (prompt v3) · confidence: 95%