CVE-2009-0170

CWE-255CWE-2643 documents3 sources
Severity
6.0MEDIUM
EPSS
0.8%
top 25.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 16
Latest updateMay 2

Description

Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1 allows remote authenticated users with console privileges to discover passwords, and obtain unspecified other "access to resources," by visiting the Configuration Items component in the console.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 6.8 | Impact: 6.4

Affected Packages1 packages

NVDsun/java_system_access_manager6.3, 7.0_2005q4, 7.1+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-78gh-v8vr-85ch: Sun Java System Access Manager 62022-05-02
CVEList
CVE-2009-0170: Sun Java System Access Manager 62009-01-16