CVE-2008-2402
The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read password hashes and configuration data via direct requests…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.4%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read password hashes and configuration data via direct requests for unspecified documents.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 11.37% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- sun/java asp server
- Source
- cve@mitre.org
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=706
- http://secunia.com/advisories/30523
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-238184-1Patch
- http://www.securityfocus.com/bid/29540
- http://www.securitytracker.com/id?1020187
- http://www.vupen.com/english/advisories/2008/1742/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42828
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=706
- http://secunia.com/advisories/30523
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-238184-1Patch
- http://www.securityfocus.com/bid/29540
- http://www.securitytracker.com/id?1020187
- http://www.vupen.com/english/advisories/2008/1742/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42828
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.