CVE Vulnerabilities

CVE-2009-2713

Published: Aug 07, 2009 | Modified: Aug 15, 2009
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The CDCServlet component in Sun Java System Access Manager 7.0 2005Q4 and 7.1, when Cross Domain Single Sign On (CDSSO) is enabled, does not ensure that policy advice is presented to the correct client, which allows remote attackers to obtain sensitive information via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Java_system_access_manager Sun 6.3_2005q1 (including) 6.3_2005q1 (including)
Java_system_access_manager Sun 7.1 (including) 7.1 (including)
Java_system_access_manager Sun 7_2005q4 (including) 7_2005q4 (including)

References