Vulnerability Name: | CVE-2009-1074 (CCN-49608) | ||||||||
Assigned: | 2009-03-19 | ||||||||
Published: | 2009-03-19 | ||||||||
Updated: | 2009-10-06 | ||||||||
Summary: | Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to "ssl termination devices" and lack of support for relative URLs. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-310 | ||||||||
Vulnerability Consequences: | Other | ||||||||
References: | Source: CONFIRM Type: Patch http://blogs.sun.com/security/entry/sun_alert_253267_sun_java Source: MITRE Type: CNA CVE-2009-1074 Source: CCN Type: SA34380 Sun Java System Identity Manager Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 34380 Source: CCN Type: SECTRACK ID: 1021881 Sun Java System Identity Manager Bugs Let Local and Remote Users Gain Privileges Source: SECTRACK Type: UNKNOWN 1021881 Source: CONFIRM Type: Patch, Vendor Advisory http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1 Source: CCN Type: Sun Alert ID: 253267 Sun Java System Identity Manager Security Vulnerabilities Source: SUNALERT Type: Patch, Vendor Advisory 253267 Source: CCN Type: OSVDB ID: 53156 Sun Java System Identity Manager SSL Connection Fallback Weakness Source: BID Type: Exploit, Patch 34191 Source: CCN Type: BID-34191 Sun Java System Identity Manager Multiple Vulnerabilities Source: VUPEN Type: Vendor Advisory ADV-2009-0797 Source: XF Type: UNKNOWN jsim-ssl-weak-security(49608) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |