Vulnerability Name:

CVE-2007-5153 (CCN-36847)

Assigned:2007-09-27
Published:2007-09-27
Updated:2017-07-29
Summary:Unspecified vulnerability in Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 8.x container, allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS v3 Severity:5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:W/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
4.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:W/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-94
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2007-5153

Source: OSVDB
Type: UNKNOWN
37757

Source: CCN
Type: SA26976
Sun Java System Access Manager Two Security Issues

Source: SECUNIA
Type: UNKNOWN
26976

Source: CCN
Type: SECTRACK ID: 1018753
Sun Java System Access Manager Bugs Let Remote Users Access Applications Without Authenticating and Execute Arbitrary Code

Source: SECTRACK
Type: UNKNOWN
1018753

Source: CCN
Type: Sun Alert ID: 103069
Installation of Sun Java System Access Manager 7.1 on Sun Java System Application Server 9.1 or 8.x May Compromise Application Server Security

Source: SUNALERT
Type: UNKNOWN
103069

Source: SUNALERT
Type: UNKNOWN
200839

Source: CCN
Type: ASA-2007-409
Installation of Sun Java System Access Manager 7.1 on Sun Java System Application Server 9.1 or 8.x May Compromise Application Server Security (Sun 103069)

Source: CCN
Type: OSVDB ID: 37757
Sun Java System Access Manager Unspecified Remote Code Execution

Source: BID
Type: UNKNOWN
25842

Source: CCN
Type: BID-25842
Sun Java System Access Manager Multiple Vulnerabilities

Source: VUPEN
Type: UNKNOWN
ADV-2007-3282

Source: XF
Type: UNKNOWN
sun-jsam-container-code-execution(36847)

Source: XF
Type: UNKNOWN
sun-jsam-container-code-execution(36847)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sun:java_system_access_manager:7.1:*:hp-ux:*:*:*:*:*
  • OR cpe:/a:sun:java_system_access_manager:7.1:*:linux:*:*:*:*:*
  • OR cpe:/a:sun:java_system_access_manager:7.1:*:solaris_sparc:*:*:*:*:*
  • OR cpe:/a:sun:java_system_access_manager:7.1:*:solaris_x86:*:*:*:*:*
  • OR cpe:/a:sun:java_system_access_manager:7.1:*:windows:*:*:*:*:*
  • OR cpe:/a:sun:java_system_application_server:8.1:*:*:*:*:*:*:*
  • OR cpe:/a:sun:java_system_application_server:8.1:ur1:*:*:*:*:*:*
  • OR cpe:/a:sun:java_system_application_server:8.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:sun:java_system_access_manager:7.1:*:*:*:*:*:*:*
  • AND
  • cpe:/o:sun:solaris:8::x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:8::sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9::x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10::sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10::x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9::sparc:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sun java system access manager 7.1
    sun java system access manager 7.1
    sun java system access manager 7.1
    sun java system access manager 7.1
    sun java system access manager 7.1
    sun java system application server 8.1
    sun java system application server 8.1 ur1
    sun java system application server 8.2
    sun java system access manager 7.1
    sun solaris 8
    sun solaris 8
    sun solaris 9
    sun solaris 10
    sun solaris 10
    sun solaris 9