Vulnerability Name: | CVE-2009-0170 (CCN-47942) | ||||||||
Assigned: | 2009-01-12 | ||||||||
Published: | 2009-01-12 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1 allows remote authenticated users with console privileges to discover passwords, and obtain unspecified other "access to resources," by visiting the Configuration Items component in the console. | ||||||||
CVSS v3 Severity: | 2.0 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 6.0 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P) 4.4 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
2.1 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:M/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-255 CWE-264 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-0170 Source: CCN Type: SA33553 Sun Java System Access Manager Password Disclosure Security Issue Source: CCN Type: SECTRACK ID: 1021605 Sun Java System Access Manager Discloses Passwords to Remote Authenticated Administrative Users Source: CONFIRM Type: Patch, Vendor Advisory http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-02-1 Source: SUNALERT Type: Patch, Vendor Advisory 242166 Source: CCN Type: Sun Alert ID: 242166 Security Vulnerability in Sun Java System Access Manager May Allow Unauthorized Access Through Revealed Passwords Source: CCN Type: ASA-2009-027 Security Vulnerability in Sun Java System Access Manager May Allow Unauthorized Access Through Revealed Passwords (Sun 242166) Source: CCN Type: OSVDB ID: 51381 Sun Java System Access Manager Unspecified Password Disclosure Source: BID Type: Patch 33265 Source: CCN Type: BID-33265 Sun Java System Access Manager Information Disclosure Vulnerability Source: SECTRACK Type: UNKNOWN 1021605 Source: VUPEN Type: UNKNOWN ADV-2009-0156 Source: XF Type: UNKNOWN sun-jsam-password-info-disclosure(47942) Source: XF Type: UNKNOWN sun-jsam-password-info-disclosure(47942) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |