CVE-2009-1078

CWE-2643 documents3 sources
Severity
4.0MEDIUM
EPSS
0.5%
top 33.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25
Latest updateMay 2

Description

Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying workflows, which allows remote authenticated users to have an unspecified impact.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wfh8-668f-q6jm: Sun Java System Identity Manager (IdM) 72022-05-02
CVEList
CVE-2009-1078: Sun Java System Identity Manager (IdM) 72009-03-25