Lucene search

K
cveMitreCVE-2007-1681
HistoryApr 19, 2007 - 10:19 a.m.

CVE-2007-1681

2007-04-1910:19:00
mitre
web.nvd.nist.gov
35
cve-2007-1681
format string vulnerability
sun java web console
remote attackers
denial of service
sensitive information
arbitrary code
failed login attempt

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.7

Confidence

Low

EPSS

0.084

Percentile

94.4%

Format string vulnerability in libwebconsole_services.so in Sun Java Web Console 2.2.2 through 2.2.5 allows remote attackers to cause a denial of service (application crash), obtain sensitive information, and possibly execute arbitrary code via unspecified vectors during a failed login attempt, related to syslog.

Affected configurations

Nvd
Node
sunjava_web_consoleMatch2.2.2x86
OR
sunjava_web_consoleMatch2.2.3x86
OR
sunjava_web_consoleMatch2.2.4x86
OR
sunjava_web_consoleMatch2.2.5x86
Node
sunsolarisMatch10.0x86
OR
sunsolarisMatch10.0hw2
Node
sunjava_web_consoleMatch2.2.2x86
OR
sunjava_web_consoleMatch2.2.3x86
OR
sunjava_web_consoleMatch2.2.4x86
OR
sunjava_web_consoleMatch2.2.5x86
VendorProductVersionCPE
sunjava_web_console2.2.2cpe:2.3:a:sun:java_web_console:2.2.2:*:x86:*:*:*:*:*
sunjava_web_console2.2.3cpe:2.3:a:sun:java_web_console:2.2.3:*:x86:*:*:*:*:*
sunjava_web_console2.2.4cpe:2.3:a:sun:java_web_console:2.2.4:*:x86:*:*:*:*:*
sunjava_web_console2.2.5cpe:2.3:a:sun:java_web_console:2.2.5:*:x86:*:*:*:*:*
sunsolaris10.0cpe:2.3:o:sun:solaris:10.0:*:x86:*:*:*:*:*
sunsolaris10.0cpe:2.3:o:sun:solaris:10.0:hw2:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.7

Confidence

Low

EPSS

0.084

Percentile

94.4%