CVE-2004-1354Path Traversal in Solaris

CWE-22Path Traversal3 documents3 sources
Severity
5.0MEDIUMNVD
EPSS
3.3%
top 12.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 14
Latest updateApr 29

Description

The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inaccessible, which could allow remote attackers to obtain sensitive information in conjunction with a directory traversal (..) attack.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDsun/solaris8.0, 9.0+1
NVDsun/sunos5.8

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4439-mj69-f3rc: The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exist2022-04-29
CVEList
CVE-2004-1354: The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exist2005-01-19
CVE-2004-1354 — Path Traversal in SUN Solaris | cvebase