Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container restart, which allows remote attackers to perform administrative tasks.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Java_system_access_manager | Sun | 7.1 (including) | 7.1 (including) |
Java_system_application_server | Sun | 9.1 (including) | 9.1 (including) |