cbcvebase.
CVE-2009-1078
published 2009-03-25

CVE-2009-1078: Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying…

PriorityP420medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
1.80%
76.1th percentile
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying workflows, which allows remote authenticated users to have an unspecified impact.

Affected

4 ranges
VendorProductVersion rangeFixed in
sunjava_system_identity_manager
sunjava_system_identity_manager
sunjava_system_identity_manager
sunjava_system_identity_manager
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.