Lucene search

K
cve[email protected]CVE-2009-2268
HistoryJul 01, 2009 - 1:00 p.m.

CVE-2009-2268

2009-07-0113:00:01
CWE-79
web.nvd.nist.gov
24
cve-2009-2268
cross-site scripting
xss
sun java system access manager
remote attackers
web script
html
vulnerability
nvd

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

5.5 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.8%

Cross-site scripting (XSS) vulnerability in the Cross-Domain Controller (CDC) servlet in Sun Java System Access Manager 6 2005Q1, 7 2005Q4, and 7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected configurations

NVD
Node
sunjava_system_access_managerMatch6
OR
sunjava_system_access_managerMatch6.0_2005q1linux
OR
sunjava_system_access_managerMatch6.0_2005q1solaris_10_sparc
OR
sunjava_system_access_managerMatch6.0_2005q1solaris_10_x86
OR
sunjava_system_access_managerMatch6.0_2005q1solaris_8_sparc
OR
sunjava_system_access_managerMatch6.0_2005q1solaris_8_x86
OR
sunjava_system_access_managerMatch6.0_2005q1solaris_9_sparc
OR
sunjava_system_access_managerMatch6.0_2005q1solaris_9_x86
OR
sunjava_system_access_managerMatch7.0
OR
sunjava_system_access_managerMatch7.0_2005q4hp-ux
OR
sunjava_system_access_managerMatch7.0_2005q4linux
OR
sunjava_system_access_managerMatch7.0_2005q4solaris10_x86
OR
sunjava_system_access_managerMatch7.0_2005q4solaris9_x86
OR
sunjava_system_access_managerMatch7.0_2005q4windows
OR
sunjava_system_access_managerMatch7.1
OR
sunjava_system_access_managerMatch7.1linux
OR
sunjava_system_access_managerMatch7.1solaris_10_sparc
OR
sunjava_system_access_managerMatch7.1solaris_10_x86
OR
sunjava_system_access_managerMatch7.1solaris_8_sparc
OR
sunjava_system_access_managerMatch7.1solaris_8_x86
OR
sunjava_system_access_managerMatch7.1solaris_9_sparc
OR
sunjava_system_access_managerMatch7.1solaris_9_x86
OR
sunjava_system_access_managerMatch7.1windows
OR
sunjava_system_access_managerMatch7_2005q4solaris_10_sparc
OR
sunjava_system_access_managerMatch7_2005q4solaris_8_sparc
OR
sunjava_system_access_managerMatch7_2005q4solaris_9_sparc

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

5.5 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.8%

Related for CVE-2009-2268