PT-2007-2813 · Oracle · Java Dynamic Management Kit
Published
2007-03-12
·
Updated
2011-03-08
·
CVE-2007-1419
CVSS v2.0
4.3
Medium
| Vector | AV:L/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Java Dynamic Management Kit version 5.1 before 20070309
Description
The issue concerns the Java Management Extensions Remote API Remote Method Invocation over Internet Inter-ORB Protocol (JMX RMI-IIOP) API, which does not properly enforce the java.policy. This allows local users to obtain certain MBeans data access by operating a server application accessed by a privileged remote authenticated user.
Recommendations
For Java Dynamic Management Kit version 5.1 before 20070309, update to a version released after 20070309 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Java Dynamic Management Kit