Vulnerability Name: | CVE-2009-0169 (CCN-47944) | ||||||||
Assigned: | 2009-01-12 | ||||||||
Published: | 2009-01-12 | ||||||||
Updated: | 2017-08-08 | ||||||||
Summary: | Sun Java System Access Manager 7.1 allows remote authenticated sub-realm administrators to gain privileges, as demonstrated by creating the amadmin account in the sub-realm, and then logging in as amadmin in the root realm. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C) 6.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-0169 Source: CCN Type: SA33554 Sun Java System Access Manager Privilege Escalation Vulnerability Source: CCN Type: SECTRACK ID: 1021604 Sun Java System Access Manager Lets Remote Authenticated Users Gain Elevated Privileges Source: CONFIRM Type: Patch, Vendor Advisory http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-02-1 Source: SUNALERT Type: Vendor Advisory 249106 Source: CCN Type: Sun Alert ID: 249106 A Security Vulnerability in Sun Java System Access Manager May Allow Privilege Escalation of Sub-Realm Administrators Source: CCN Type: ASA-2009-031 A Security Vulnerability in Sun Java System Access Manager May Allow Privilege Escalation of Sub-Realm Administrators (Sun 249106) Source: CCN Type: OSVDB ID: 51382 Sun Java System Access Manager Unspecified Privilege Escalation Source: BID Type: Patch 33266 Source: CCN Type: BID-33266 Sun Java System Access Manager 'sub-realm' Privilege Escalation Vulnerability Source: SECTRACK Type: UNKNOWN 1021604 Source: VUPEN Type: UNKNOWN ADV-2009-0157 Source: XF Type: UNKNOWN sun-jsam-subrealm-privilege-escalation(47944) Source: XF Type: UNKNOWN sun-jsam-subrealm-privilege-escalation(47944) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |