HIGH
Directory traversal vulnerability in idm/includes/helpServer.jsp in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to read arbitrary files in the filesystem of the IDM server via directory traversal sequences in the ext parameter
Published Nov 18, 2008
7.8
HIGHCVSS 2.0
EPSS 4.11%
Description
Directory traversal vulnerability in idm/includes/helpServer.jsp in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to read arbitrary files in the filesystem of the IDM server via directory traversal sequences in the ext parameter.
Affected products
No data.
OR
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 7.0
- 7.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- http://osvdb.org/49767 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/32606 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-243386-1 vendor-advisoryx_refsource_SUNALERTPatchVendor Advisory
- http://www.procheckup.com/Vulnerability_PR08-09.php x_refsource_MISC
- http://www.securityfocus.com/archive/1/498487/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/32262 vdb-entryx_refsource_BIDExploit
- http://www.securitytracker.com/id?1021170 vdb-entryx_refsource_SECTRACK
- http://www.vupen.com/english/advisories/2008/3128 vdb-entryx_refsource_VUPENVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2008-5095 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46554 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://osvdb.org/49767 | vdb-entryx_refsource_OSVDB | |
| http://secunia.com/advisories/32606 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://sunsolve.sun.com/search/document.do?assetkey=1-26-243386-1 | vendor-advisoryx_refsource_SUNALERTPatchVendor Advisory | |
| http://www.procheckup.com/Vulnerability_PR08-09.php | x_refsource_MISC | |
| http://www.securityfocus.com/archive/1/498487/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/32262 | vdb-entryx_refsource_BIDExploit | |
| http://www.securitytracker.com/id?1021170 | vdb-entryx_refsource_SECTRACK | |
| http://www.vupen.com/english/advisories/2008/3128 | vdb-entryx_refsource_VUPENVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2008-5095 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/46554 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 18, 2008
Updated Aug 7, 2024
Reserved Nov 17, 2008
Link CVE-2008-5116
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2008-5095 Assigner mitre
Published Nov 18, 2008
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2008-5095