Sun Java System Access Manager の CDCServlet コンポーネントにおける重要な情報を取得される脆弱性
| Title |
Sun Java System Access Manager の CDCServlet コンポーネントにおける重要な情報を取得される脆弱性
|
| Summary |
Sun Java System Access Manager の CDCServlet コンポーネントは、Cross Domain Single Sign On (CDSSO) が有効になっている際、"ポリシーアドバイス" が正しいクライアントに提示されているか確認しないため、重要な情報を取得される脆弱性が存在します。
|
| Possible impacts |
第三者により、重要な情報を取得される可能性があります。 |
| Solution |
ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date |
Aug. 5, 2009, midnight |
| Registration Date |
Dec. 20, 2012, 7:10 p.m. |
| Last Update |
Dec. 20, 2012, 7:10 p.m. |
|
CVSS2.0 : 警告
|
| Score |
4.3
|
| Vector |
AV:N/AC:M/Au:N/C:P/I:N/A:N |
Affected System
| サン・マイクロシステムズ |
|
java system access manager 7.0 2005Q4 および 7.1
|
|
Sun Java System Web Server
|
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
| No |
Changed Details |
Date of change |
| 0 |
[2012年12月20日] 掲載 |
Feb. 17, 2018, 10:37 a.m. |
NVD Vulnerability Information
CVE-2009-2713
| Summary |
The CDCServlet component in Sun Java System Access Manager 7.0 2005Q4 and 7.1, when Cross Domain Single Sign On (CDSSO) is enabled, does not ensure that "policy advice" is presented to the correct client, which allows remote attackers to obtain sensitive information via unspecified vectors.
|
| Publication Date |
Aug. 8, 2009, 4 a.m. |
| Registration Date |
Jan. 29, 2021, 1:21 p.m. |
| Last Update |
Aug. 15, 2009, 2:23 p.m. |
Affected software configurations
| Configuration1 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_10_sparc:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_8_sparc:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_9_sparc:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_10_sparc:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_8_sparc:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_9_sparc:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_10_sparc:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_8_sparc:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_9_sparc:*:*:*:*:* |
|
|
|
|
| Configuration2 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_10_x86:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_8_x86:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_9_x86:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_10_x86:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_8_x86:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_9_x86:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_10_x86:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_8_x86:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_9_x86:*:*:*:*:* |
|
|
|
|
| Configuration3 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_10_linux:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_8_linux:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_9_linux:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_10_linux:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_8_linux:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_9_linux:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_10_linux:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_8_linux:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_9_linux:*:*:*:*:* |
|
|
|
|
| Configuration4 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:sun:java_system_access_manager:7.0_2005q4:*:windows:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sun:java_system_access_manager:7.1:*:windows:*:*:*:*:* |
|
|
|
|
| Configuration5 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:sun:java_system_web_server:7.0:*:hp_ux:*:*:*:*:* |
|
|
|
|
| Configuration6 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:sun:java_system_access_manager:7.1:*:war:*:*:*:*:* |
|
|
|
|
Related information, measures and tools
Common Vulnerabilities List