PT-2007-2916 · Sun · Sun Java System Web Server

Published

2007-03-20

·

Updated

2011-03-08

·

CVE-2007-1526

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sun Java System Web Server version 6.1 before 20070314
Description The issue allows remote authenticated users with revoked client certificates to bypass the Certificate Revocation List (CRL) authorization control. This enables access to secure web server instances running under an account different from that used for the admin server.
Recommendations For Sun Java System Web Server version 6.1 before 20070314, update to a version released after 20070314 to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1526

Affected Products

Sun Java System Web Server