PT-2007-2916 · Sun · Sun Java System Web Server
Published
2007-03-20
·
Updated
2011-03-08
·
CVE-2007-1526
CVSS v2.0
6.0
Medium
| Vector | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Sun Java System Web Server version 6.1 before 20070314
Description
The issue allows remote authenticated users with revoked client certificates to bypass the Certificate Revocation List (CRL) authorization control. This enables access to secure web server instances running under an account different from that used for the admin server.
Recommendations
For Sun Java System Web Server version 6.1 before 20070314, update to a version released after 20070314 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sun Java System Web Server