Vulnerability Name: | CVE-2008-2705 (CCN-43004) | ||||||||
Assigned: | 2008-06-11 | ||||||||
Published: | 2008-06-11 | ||||||||
Updated: | 2017-08-08 | ||||||||
Summary: | Unspecified vulnerability in Sun Java System Access Manager (AM) 7.1, when used with certain versions and configurations of Sun Directory Server Enterprise Edition (DSEE), allows remote attackers to bypass authentication via unspecified vectors. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-287 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-2705 Source: CCN Type: SA30652 Sun Java Access Manager Unspecified Security Bypass Source: SECUNIA Type: Vendor Advisory 30652 Source: CCN Type: SECTRACK ID: 1020273 Sun Java System Access Manager Grants Administrator Access to Remote Users Source: SUNALERT Type: UNKNOWN 238416 Source: CCN Type: Sun Alert ID: 238416 A Vulnerability in Access Manager 7.1 may Allow Unauthorized Access to Resources Source: CCN Type: OSVDB ID: 46149 Sun Java System Access Manager Unspecified Remote Authentication Bypass Source: BID Type: UNKNOWN 29676 Source: CCN Type: BID-29676 Sun Java System Access Manager Authentication Bypass Vulnerability Source: SECTRACK Type: UNKNOWN 1020273 Source: VUPEN Type: UNKNOWN ADV-2008-1806 Source: XF Type: UNKNOWN sun-jsam-unspecified-security-bypass(43004) Source: XF Type: UNKNOWN sun-jsam-unspecified-security-bypass(43004) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |