CVE-2009-1084

Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated administrators and possibly remote attackers to have an unspecified impact by modifying this object.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sun:java_system_identity_manager:7.0:*:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_identity_manager:7.1:*:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_identity_manager:7.1.1:*:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_identity_manager:8.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:01

Type Values Removed Values Added
References () http://blogs.sun.com/security/entry/sun_alert_253267_sun_java - Patch () http://blogs.sun.com/security/entry/sun_alert_253267_sun_java - Patch
References () http://secunia.com/advisories/34380 - Vendor Advisory () http://secunia.com/advisories/34380 - Vendor Advisory
References () http://securitytracker.com/id?1021881 - () http://securitytracker.com/id?1021881 -
References () http://sunsolve.sun.com/search/document.do?assetkey=1-21-139010-06-1 - Patch () http://sunsolve.sun.com/search/document.do?assetkey=1-21-139010-06-1 - Patch
References () http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1 - Patch () http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1 - Patch
References () http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1 - Patch, Vendor Advisory () http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1 - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/34191 - () http://www.securityfocus.com/bid/34191 -
References () http://www.vupen.com/english/advisories/2009/0797 - Vendor Advisory () http://www.vupen.com/english/advisories/2009/0797 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/49607 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/49607 -

Information

Published : 2009-03-25 15:30

Updated : 2024-11-21 01:01


NVD link : CVE-2009-1084

Mitre link : CVE-2009-1084

CVE.ORG link : CVE-2009-1084


JSON object : View

Products Affected

sun

  • java_system_identity_manager
CWE
CWE-264

Permissions, Privileges, and Access Controls