CVE Vulnerabilities

CVE-2009-1077

Published: Mar 25, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresChallenge property setting, which allows remote authenticated users to change the passwords of other users, as demonstrated by changing the administrators password.

Affected Software

NameVendorStart VersionEnd Version
Java_system_identity_managerSun7.0 (including)7.0 (including)
Java_system_identity_managerSun7.1 (including)7.1 (including)
Java_system_identity_managerSun7.1.1 (including)7.1.1 (including)
Java_system_identity_managerSun8.0 (including)8.0 (including)

References