cbcvebase.
CVE-2009-1082
published 2009-03-25

CVE-2009-1082: Sun Java System Identity Manager (IdM) 7.0 through 8.0 allows remote authenticated users to gain privileges by submitting crafted commands to the Admin…

PriorityP348critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
3.44%
87.7th percentile
Sun Java System Identity Manager (IdM) 7.0 through 8.0 allows remote authenticated users to gain privileges by submitting crafted commands to the Admin Console, as demonstrated by privileges for account creation and other administrative capabilities, related to the saveNoValidate action and saveNoValidateAllowedFormsAndWorkflows IDs.

Affected

4 ranges
VendorProductVersion rangeFixed in
sunjava_system_identity_manager
sunjava_system_identity_manager
sunjava_system_identity_manager
sunjava_system_identity_manager
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.