MEDIUM
The CDCServlet component in Sun Java System Access Manager 7.0 2005Q4 and 7.1, when Cross Domain Single Sign On (CDSSO) is enabled, does not ensure that "policy advice" is presented to the correct client, which allows remote attackers to obtain sensitive information via unspecified vectors
Published Aug 7, 2009
4.3
MEDIUMCVSS 2.0
EPSS 1.71%
Description
The CDCServlet component in Sun Java System Access Manager 7.0 2005Q4 and 7.1, when Cross Domain Single Sign On (CDSSO) is enabled, does not ensure that "policy advice" is presented to the correct client, which allows remote attackers to obtain sensitive information via unspecified vectors.
Affected products
No data.
Configuration 1
OR
- 6.3_2005q1
- 6.3_2005q1
- 6.3_2005q1
- 7.1
- 7.1
- 7.1
- 7_2005q4
- 7_2005q4
- 7_2005q4
Configuration 2
OR
- 6.3_2005q1
- 6.3_2005q1
- 6.3_2005q1
- 7.1
- 7.1
- 7.1
- 7_2005q4
- 7_2005q4
- 7_2005q4
Configuration 3
OR
- 6.3_2005q1
- 6.3_2005q1
- 6.3_2005q1
- 7.1
- 7.1
- 7.1
- 7_2005q4
- 7_2005q4
- 7_2005q4
Configuration 4
OR
- 7.0_2005q4
- 7.1
Configuration 5
- 7.0
Configuration 6
- 7.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (6)
- http://secunia.com/advisories/36167 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-03-1 x_refsource_CONFIRMPatch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-255968-1 vendor-advisoryx_refsource_SUNALERTVendor Advisory
- http://www.securityfocus.com/bid/35961 vdb-entryx_refsource_BIDPatch
- http://www.vupen.com/english/advisories/2009/2176 vdb-entryx_refsource_VUPEN
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-2704 Advisory
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/36167 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-03-1 | x_refsource_CONFIRMPatch | |
| http://sunsolve.sun.com/search/document.do?assetkey=1-66-255968-1 | vendor-advisoryx_refsource_SUNALERTVendor Advisory | |
| http://www.securityfocus.com/bid/35961 | vdb-entryx_refsource_BIDPatch | |
| http://www.vupen.com/english/advisories/2009/2176 | vdb-entryx_refsource_VUPEN | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-2704 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 7, 2009
Updated Aug 7, 2024
Reserved Aug 7, 2009
Link CVE-2009-2713
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-2704 Assigner mitre
Published Aug 7, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-2704