VulnerabilityModified
CVE-2009-1078
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying workflows, which allows remote authenticated users to have an unspecified impact.
MEDIUM 4.0EPSS 1.80%
Does this matter?
Lower severity and a low EPSS score (1.80%). Track it; it rarely justifies an emergency change on its own.
Description
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying workflows, which allows remote authenticated users to have an unspecified impact.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
- EPSS
- 1.80% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- sun/java system identity manager
- Source
- cve@mitre.org
References
- http://blogs.sun.com/security/entry/sun_alert_253267_sun_javaPatch, Vendor Advisory
- http://secunia.com/advisories/34380Vendor Advisory
- http://securitytracker.com/id?1021881
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1Patch, Vendor Advisory
- http://www.securityfocus.com/bid/34191Exploit, Patch
- http://www.vupen.com/english/advisories/2009/0797Vendor Advisory
- http://blogs.sun.com/security/entry/sun_alert_253267_sun_javaPatch, Vendor Advisory
- http://secunia.com/advisories/34380Vendor Advisory
- http://securitytracker.com/id?1021881
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1Patch, Vendor Advisory
- http://www.securityfocus.com/bid/34191Exploit, Patch
- http://www.vupen.com/english/advisories/2009/0797Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.