Lucene search

K
cveMitreCVE-2009-1084
HistoryMar 25, 2009 - 3:30 p.m.

CVE-2009-1084

2009-03-2515:30:00
CWE-264
mitre
web.nvd.nist.gov
26
cve-2009-1084
sun java
identity manager
access restriction
remote attackers
nvd

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.002

Percentile

58.5%

Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated administrators and possibly remote attackers to have an unspecified impact by modifying this object.

Affected configurations

Nvd
Node
sunjava_system_identity_managerMatch7.0
OR
sunjava_system_identity_managerMatch7.1
OR
sunjava_system_identity_managerMatch7.1.1
OR
sunjava_system_identity_managerMatch8.0
VendorProductVersionCPE
sunjava_system_identity_manager7.0cpe:2.3:a:sun:java_system_identity_manager:7.0:*:*:*:*:*:*:*
sunjava_system_identity_manager7.1cpe:2.3:a:sun:java_system_identity_manager:7.1:*:*:*:*:*:*:*
sunjava_system_identity_manager7.1.1cpe:2.3:a:sun:java_system_identity_manager:7.1.1:*:*:*:*:*:*:*
sunjava_system_identity_manager8.0cpe:2.3:a:sun:java_system_identity_manager:8.0:*:*:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.002

Percentile

58.5%

Related for CVE-2009-1084