SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-1074

Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to "ssl termination devices" and lack of…

MEDIUM 5.0EPSS 2.46%

Does this matter?

Lower severity and a low EPSS score (2.46%). Track it; it rarely justifies an emergency change on its own.

Description

Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to "ssl termination devices" and lack of support for relative URLs.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
2.46% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
sun/java system identity manager
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.