PT-2009-3656 · Sun · Sun Java System Identity Manager

Publicado

2009-03-25

·

Atualizado

2009-10-06

·

CVE-2009-1077

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sun Java System Identity Manager versions 7.0 through 8.0
Description The issue concerns the Change My Password feature in the admin interface, which fails to enforce the RequiresChallenge property setting. This allows remote authenticated users to change the passwords of other users without proper authorization, potentially leading to unauthorized access and changes to sensitive accounts.
Recommendations For Sun Java System Identity Manager versions 7.0 through 8.0, ensure that the RequiresChallenge property is properly enforced to prevent unauthorized password changes. Consider temporarily restricting access to the Change My Password feature in the admin interface until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-1077

Produtos afetados

Sun Java System Identity Manager