Sun / Java System Identity Manager
19 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2009-1084 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated… | MEDIUM | 6.4 | Mar 25, 2009 |
| CVE-2009-1083 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 on Linux, AIX, Solaris, and HP-UX permits "control characters" in the passwords of user accounts, which… | HIGH | 9.0 | Mar 25, 2009 |
| CVE-2009-1082 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 allows remote authenticated users to gain privileges by submitting crafted commands to the Admin Console… | HIGH | 9.0 | Mar 25, 2009 |
| CVE-2009-1081 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web sc… | MEDIUM | 4.3 | Mar 25, 2009 |
| CVE-2009-1080 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web sc… | MEDIUM | 4.3 | Mar 25, 2009 |
| CVE-2009-1079 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web sc… | MEDIUM | 4.3 | Mar 25, 2009 |
| CVE-2009-1078 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying w… | MEDIUM | 4.0 | Mar 25, 2009 |
| CVE-2009-1077 | The Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresChallenge p… | MEDIUM | 6.5 | Mar 25, 2009 |
| CVE-2009-1076 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the end-user question-based login feature depending on whether the… | MEDIUM | 5.0 | Mar 25, 2009 |
| CVE-2009-1075 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the Forgot Password feature depending on whether the user account… | MEDIUM | 5.0 | Mar 25, 2009 |
| CVE-2009-1074 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to obtain sen… | MEDIUM | 5.0 | Mar 25, 2009 |
| CVE-2008-5118 | Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attac… | MEDIUM | 4.3 | Nov 18, 2008 |
| CVE-2008-5117 | Open redirect vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web si… | MEDIUM | 6.4 | Nov 18, 2008 |
| CVE-2008-5116 | Directory traversal vulnerability in idm/includes/helpServer.jsp in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers… | HIGH | 7.8 | Nov 18, 2008 |
| CVE-2008-5115 | Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hijack the aut… | MEDIUM | 6.8 | Nov 18, 2008 |
| CVE-2008-5114 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allow remote attackers to inject arbi… | MEDIUM | 4.3 | Nov 18, 2008 |
| CVE-2008-0241 | Open redirect vulnerability in /idm/user/login.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to redirect us… | MEDIUM | 5.8 | Jan 11, 2008 |
| CVE-2008-0240 | /idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and… | MEDIUM | 4.3 | Jan 11, 2008 |
| CVE-2008-0239 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote attackers to inject arbi… | MEDIUM | 4.3 | Jan 11, 2008 |
Showing 1 to 19 of 19 CVEs