| Vulnerability Name: | CVE-2009-1553 (CCN-50335) | ||||||||||||||||||||||||
| Assigned: | 2009-05-05 | ||||||||||||||||||||||||
| Published: | 2009-05-05 | ||||||||||||||||||||||||
| Updated: | 2018-10-10 | ||||||||||||||||||||||||
| Summary: | Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) applications/applications.jsf, (2) configuration/configuration.jsf, (3) customMBeans/customMBeans.jsf, (4) resourceNode/resources.jsf, (5) sysnet/registration.jsf, or (6) webService/webServicesGeneral.jsf; or the name parameter to (7) configuration/auditModuleEdit.jsf, (8) configuration/httpListenerEdit.jsf, or (9) resourceNode/jdbcResourceEdit.jsf. | ||||||||||||||||||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.9 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:TF/RC:C)
3.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:TF/RC:C)
| ||||||||||||||||||||||||
| Vulnerability Type: | CWE-79 | ||||||||||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2009-1553 Source: CCN Type: DSECRG-09-034 Sun Glassfish Enterprise Server - Multiple Linked XSS vulnerabilies Source: MISC Type: Exploit http://dsecrg.com/pages/vul/show.php?id=134 Source: JVN Type: UNKNOWN JVN#73653977 Source: JVNDB Type: UNKNOWN JVNDB-2009-000027 Source: OSVDB Type: UNKNOWN 54249 Source: OSVDB Type: UNKNOWN 54250 Source: OSVDB Type: UNKNOWN 54251 Source: OSVDB Type: UNKNOWN 54252 Source: OSVDB Type: UNKNOWN 54253 Source: OSVDB Type: UNKNOWN 54254 Source: OSVDB Type: UNKNOWN 54255 Source: OSVDB Type: UNKNOWN 54256 Source: OSVDB Type: UNKNOWN 54257 Source: CCN Type: SA35009 Glassfish Multiple Cross-Site Scripting Vulnerabilities Source: SUNALERT Type: UNKNOWN 258528 Source: MLIST Type: Exploit [dev] 20090319 [DSECRG] Sun Glassfish Multiple Security Vulnerabilities Source: MLIST Type: UNKNOWN [dev] 20090411 Re: [DSECRG] Sun Glassfish Multiple Security Vulnerabilities Source: CCN Type: OSVDB ID: 54249 Glassfish Enterprise Server Admin Console /applications/applications.jsf URI XSS Source: CCN Type: OSVDB ID: 54250 Glassfish Enterprise Server Admin Console /configuration/configuration.jsf URI XSS Source: CCN Type: OSVDB ID: 54251 Glassfish Enterprise Server Admin Console /customMBeans/customMBeans.jsf URI XSS Source: CCN Type: OSVDB ID: 54252 Glassfish Enterprise Server Admin Console /resourceNode/resources.jsf URI XSS Source: CCN Type: OSVDB ID: 54253 Glassfish Enterprise Server Admin Console /sysnet/registration.jsf URI XSS Source: CCN Type: OSVDB ID: 54254 Glassfish Enterprise Server Admin Console /webService/webServicesGeneral.jsf URI XSS Source: CCN Type: OSVDB ID: 54255 Glassfish Enterprise Server Admin Console /configuration/auditModuleEdit.jsf name Parameter XSS Source: CCN Type: OSVDB ID: 54256 Glassfish Enterprise Server Admin Console /configuration/httpListenerEdit.jsf name Parameter XSS Source: CCN Type: OSVDB ID: 54257 Glassfish Enterprise Server Admin Console /resourceNode/jdbcResourceEdit.jsf name Parameter XSS Source: BUGTRAQ Type: UNKNOWN 20090505 [DSECRG-09-034] Sun Glassfish Enterprise Server - Multiple Linked XSS vulnerabilies Source: BID Type: Exploit 34824 Source: CCN Type: BID-34824 GlassFish Enterprise Server Multiple Cross Site Scripting Vulnerabilities Source: BID Type: UNKNOWN 34914 Source: CCN Type: BID-34914 Sun GlassFish Enterprise and Sun Java System Application Server Cross Site Scripting Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2009-1255 Source: XF Type: UNKNOWN glassfish-multiple-pages-xss(50335) Source: XF Type: UNKNOWN glassfish-jsa-admininterface-xss(50453) Source: CCN Type: GlassFish CVS Repository GlassFish Source: MLIST Type: Patch, Vendor Advisory [cvs] 20090320 CVS update [SJSAS91_FCS_BRANCH]: /glassfish/admin-gui/src/java/com/sun/enterprise/tools/admingui/handlers/CommonHandlers.java Source: MLIST Type: Patch, Vendor Advisory [cvs] 20090320 CVS update [SJSAS91_FCS_BRANCH]: /glassfish/admin-gui/src/docroot/ Source: MLIST Type: Patch, Vendor Advisory [cvs] 20090322 CVS update [SJSAS91_FCS_BRANCH]: /glassfish/admin-gui/src/docroot/configuration/ | ||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||