| Vulnerability Name: | CVE-2008-2402 (CCN-42828) | ||||||||
| Assigned: | 2008-06-03 | ||||||||
| Published: | 2008-06-03 | ||||||||
| Updated: | 2017-08-08 | ||||||||
| Summary: | The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read password hashes and configuration data via direct requests for unspecified documents. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-264 | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: MITRE Type: CNA CVE-2008-2402 Source: IDEFENSE Type: UNKNOWN 20080603 Sun Java System Active Server Pages Information Disclosure Vulnerability Source: CCN Type: SA30523 Sun Java System Active Server Pages Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 30523 Source: CCN Type: SECTRACK ID: 1020187 Sun Java ASP Server Discloses Potentially Sensitive Information to Remote Users Source: CCN Type: Sun Alert ID: 238184 Multiple Security Vulnerabilities in Sun Java ASP Server may lead to execution of Arbitrary Code or Unauthorized Access to Data Source: SUNALERT Type: Patch 238184 Source: CCN Type: ASA-2008-243 Multiple Security Vulnerabilities in Sun Java ASP Server may lead to execution of Arbitrary Code or Unauthorized Access to Data (Sun 238184) Source: CCN Type: OSVDB ID: 46016 Sun Java Active Server Pages (ASP) Server Admin Server Direct Request Information Disclosure Source: BID Type: UNKNOWN 29540 Source: CCN Type: BID-29540 Sun Java ASP Server Information Disclosure Vulnerability Source: SECTRACK Type: UNKNOWN 1020187 Source: VUPEN Type: UNKNOWN ADV-2008-1742 Source: XF Type: UNKNOWN sunjava-active-password-info-disclosure(42828) Source: XF Type: UNKNOWN sunjava-active-password-info-disclosure(42828) Source: CCN Type: iDefense Labs PUBLIC ADVISORY: 06.03.08 Sun Java System Active Server Pages Information Disclosure Vulnerability | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||