CVE-2004-2766
Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02 allows remote attackers to obtain unspecified "access" to e-mail via a crafted e-mail message, related to a "session hijacking" issue, a different vulnerability…
Does this matter?
Lower severity and a low EPSS score (1.44%). Track it; it rarely justifies an emergency change on its own.
Description
Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02 allows remote attackers to obtain unspecified "access" to e-mail via a crafted e-mail message, related to a "session hijacking" issue, a different vulnerability than CVE-2005-2022 and CVE-2006-5486.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.44% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- sun/iplanet messaging server · sun/one messaging server
- Source
- cve@mitre.org
References
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-116568-55-1Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-201180-1Patch, Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-116568-55-1Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-201180-1Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.