Vulnerability Name: | CVE-2009-1075 (CCN-49609) | ||||||||
Assigned: | 2009-03-19 | ||||||||
Published: | 2009-03-19 | ||||||||
Updated: | 2009-10-06 | ||||||||
Summary: | Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the Forgot Password feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
4.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-255 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CONFIRM Type: Patch, Vendor Advisory http://blogs.sun.com/security/entry/sun_alert_253267_sun_java Source: MITRE Type: CNA CVE-2009-1075 Source: CCN Type: SA34380 Sun Java System Identity Manager Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 34380 Source: CCN Type: SECTRACK ID: 1021881 Sun Java System Identity Manager Bugs Let Local and Remote Users Gain Privileges Source: SECTRACK Type: UNKNOWN 1021881 Source: CONFIRM Type: Patch http://sunsolve.sun.com/search/document.do?assetkey=1-21-140936-01-1 Source: CCN Type: Sun Alert ID: 253267 Sun Java System Identity Manager Security Vulnerabilities Source: SUNALERT Type: Patch, Vendor Advisory 253267 Source: CCN Type: OSVDB ID: 53163 Sun Java System Identity Manager Forgot Password Feature Account Enumeration Source: BID Type: Exploit, Patch 34191 Source: CCN Type: BID-34191 Sun Java System Identity Manager Multiple Vulnerabilities Source: VUPEN Type: Vendor Advisory ADV-2009-0797 Source: XF Type: UNKNOWN jsim-forgot-password-info-disclosure(49609) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |