CVE Vulnerabilities

CVE-2009-1077

Published: Mar 25, 2009 | Modified: Oct 06, 2009
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresChallenge property setting, which allows remote authenticated users to change the passwords of other users, as demonstrated by changing the administrators password.

Affected Software

Name Vendor Start Version End Version
Java_system_identity_manager Sun 7.0 (including) 7.0 (including)
Java_system_identity_manager Sun 7.1 (including) 7.1 (including)
Java_system_identity_manager Sun 7.1.1 (including) 7.1.1 (including)
Java_system_identity_manager Sun 8.0 (including) 8.0 (including)

References