CVE-2008-5116
published 2008-11-18CVE-2008-5116: Directory traversal vulnerability in idm/includes/helpServer.jsp in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers…
PriorityP342high7.8CVSS 2.0
AVNACLAuNCCINAN
EPSS
4.03%
89.4th percentile
Directory traversal vulnerability in idm/includes/helpServer.jsp in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to read arbitrary files in the filesystem of the IDM server via directory traversal sequences in the ext parameter.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | java_system_identity_manager | — | — |
| sun | java_system_identity_manager | — | — |
| sun | java_system_identity_manager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hxp6-963m-8348: Directory traversal vulnerability in idm/includes/helpServer
ghsa_unreviewed·2022-05-14
CVE-2008-5116 [HIGH] CWE-22 GHSA-hxp6-963m-8348: Directory traversal vulnerability in idm/includes/helpServer
Directory traversal vulnerability in idm/includes/helpServer.jsp in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to read arbitrary files in the filesystem of the IDM server via directory traversal sequences in the ext parameter.
VMware
Updated service console patches.
vendor_vmware·2008-01-07·CVSS 1.2
CVE-2007-3108 [LOW] Updated service console patches.
VMSA-2008-0001: Updated service console patches.
Updated service console patches. VMware Security Advisory VMware Security Advisory Advisory ID: VMware Security Advisory Synopsis: Updated service console patches. VMware Security Advisory Issue date: VMware Security Advisory Updated on:
CVEs: CVE-2007-3108, CVE-2007-4572, CVE-2007-5116, CVE-2007-5135, CVE-2007-5191, CVE-2007-5360, CVE-2007-5398
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/49767http://secunia.com/advisories/32606http://sunsolve.sun.com/search/document.do?assetkey=1-26-243386-1http://www.procheckup.com/Vulnerability_PR08-09.phphttp://www.securityfocus.com/archive/1/498487/100/0/threadedhttp://www.securityfocus.com/bid/32262http://www.securitytracker.com/id?1021170http://www.vupen.com/english/advisories/2008/3128https://exchange.xforce.ibmcloud.com/vulnerabilities/46554http://osvdb.org/49767http://secunia.com/advisories/32606http://sunsolve.sun.com/search/document.do?assetkey=1-26-243386-1http://www.procheckup.com/Vulnerability_PR08-09.phphttp://www.securityfocus.com/archive/1/498487/100/0/threadedhttp://www.securityfocus.com/bid/32262http://www.securitytracker.com/id?1021170http://www.vupen.com/english/advisories/2008/3128https://exchange.xforce.ibmcloud.com/vulnerabilities/46554
2008-11-18
Published