CVE-2008-2705
Unspecified vulnerability in Sun Java System Access Manager (AM) 7.1, when used with certain versions and configurations of Sun Directory Server Enterprise Edition (DSEE), allows remote attackers to bypass authentication via unspecified vectors.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in Sun Java System Access Manager (AM) 7.1, when used with certain versions and configurations of Sun Directory Server Enterprise Edition (DSEE), allows remote attackers to bypass authentication via unspecified vectors.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 3.57% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- sun/java system access manager
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/30652Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-238416-1
- http://www.securityfocus.com/bid/29676
- http://www.securitytracker.com/id?1020273
- http://www.vupen.com/english/advisories/2008/1806
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43004
- http://secunia.com/advisories/30652Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-238416-1
- http://www.securityfocus.com/bid/29676
- http://www.securitytracker.com/id?1020273
- http://www.vupen.com/english/advisories/2008/1806
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43004
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.