Java System Access Manager
Sun · 15 CVEs
Unspecified vulnerability in Oracle Sun Java System Access Manager and Oracle OpenSSO 7, 7.1, and 8 allows remote attac…
Jan 19, 2011
The CDCServlet component in Sun Java System Access Manager 7.0 2005Q4 and 7.1, when Cross Domain Single Sign On (CDSSO)…
Aug 7, 2009
Sun Java System Access Manager 6.3 2005Q1, 7.0 2005Q4, and 7.1; and OpenSSO Enterprise 8.0; when AMConfig.properties en…
Aug 7, 2009
Cross-site scripting (XSS) vulnerability in the Cross-Domain Controller (CDC) servlet in Sun Java System Access Manager…
Jul 1, 2009
The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7.1 responds differently…
Jan 29, 2009
Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1 allows remote authenticated users with console privileges…
Jan 16, 2009
Sun Java System Access Manager 7.1 allows remote authenticated sub-realm administrators to gain privileges, as demonstr…
Jan 16, 2009
Sun Java System Access Manager 6.3 through 7.1 and Sun Java System Identity Server 6.1 and 6.2 do not properly process…
Jun 30, 2008
Unspecified vulnerability in Sun Java System Access Manager (AM) 7.1, when used with certain versions and configuration…
Jun 16, 2008
Multiple cross-site scripting (XSS) vulnerabilities in the Administration Console in Sun Java System Access Manager 7.1…
Mar 8, 2008
Unspecified vulnerability in Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server…
Oct 1, 2007
Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not dema…
Oct 1, 2007
Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is…
Jul 11, 2007
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Access Manager 6.1, 6.2, 6 2005Q1 (6.3), and 7 2…
Jan 31, 2007
Unspecified vulnerability in Sun Java System Access Manager 7.0 allows local users logged in as "root" to bypass authen…
Feb 4, 2006
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2010-4444 | Unspecified vulnerability in Oracle Sun Java System Access Manager and Oracle OpenSSO 7, 7.1, and 8 allows remote attackers to affect confidentiality, integrit… | MEDIUM | 2.27% | Jan 19, 2011 |
| CVE-2009-2713 | The CDCServlet component in Sun Java System Access Manager 7.0 2005Q4 and 7.1, when Cross Domain Single Sign On (CDSSO) is enabled, does not ensure that "polic… | MEDIUM | 1.71% | Aug 7, 2009 |
| CVE-2009-2712 | Sun Java System Access Manager 6.3 2005Q1, 7.0 2005Q4, and 7.1; and OpenSSO Enterprise 8.0; when AMConfig.properties enables the debug flag, allows local users… | LOW | 0.37% | Aug 7, 2009 |
| CVE-2009-2268 | Cross-site scripting (XSS) vulnerability in the Cross-Domain Controller (CDC) servlet in Sun Java System Access Manager 6 2005Q1, 7 2005Q4, and 7.1 allows remo… | LOW | 1.65% | Jul 1, 2009 |
| CVE-2009-0348 | The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7.1 responds differently to a failed login attempt depending on… | MEDIUM | 8.16% | Jan 29, 2009 |
| CVE-2009-0170 | Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1 allows remote authenticated users with console privileges to discover passwords, and obtain unspec… | MEDIUM | 1.67% | Jan 16, 2009 |
| CVE-2009-0169 | Sun Java System Access Manager 7.1 allows remote authenticated sub-realm administrators to gain privileges, as demonstrated by creating the amadmin account in… | HIGH | 2.98% | Jan 16, 2009 |
| CVE-2008-2945 | Sun Java System Access Manager 6.3 through 7.1 and Sun Java System Identity Server 6.1 and 6.2 do not properly process XSLT stylesheets in XSLT transforms in X… | HIGH | 2.80% | Jun 30, 2008 |
| CVE-2008-2705 | Unspecified vulnerability in Sun Java System Access Manager (AM) 7.1, when used with certain versions and configurations of Sun Directory Server Enterprise Edi… | HIGH | 3.57% | Jun 16, 2008 |
| CVE-2008-1204 | Multiple cross-site scripting (XSS) vulnerabilities in the Administration Console in Sun Java System Access Manager 7.1 and 7 2005Q4 allow remote attackers to… | MEDIUM | 1.66% | Mar 8, 2008 |
| CVE-2007-5153 | Unspecified vulnerability in Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 8.x container, allows remote attackers… | MEDIUM | 3.43% | Oct 1, 2007 |
| CVE-2007-5152 | Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container rest… | HIGH | 2.83% | Oct 1, 2007 |
| CVE-2007-3700 | Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is configured in the com.iplanet.services.d… | LOW | 0.32% | Jul 11, 2007 |
| CVE-2007-0628 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Access Manager 6.1, 6.2, 6 2005Q1 (6.3), and 7 2005Q4 (7.0) before 20070129 allow remote… | MEDIUM | 2.00% | Jan 31, 2007 |
| CVE-2006-0531 | Unspecified vulnerability in Sun Java System Access Manager 7.0 allows local users logged in as "root" to bypass authentication and gain top-level administrato… | HIGH | 0.40% | Feb 4, 2006 |
Showing 1 to 15 of 15 CVEs