VulnerabilityModified
CVE-2009-1084
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated administrators and possibly remote attackers to have an unspecified impact by modifying this…
MEDIUM 6.4EPSS 2.56%
Does this matter?
Lower severity and a low EPSS score (2.56%). Track it; it rarely justifies an emergency change on its own.
Description
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated administrators and possibly remote attackers to have an unspecified impact by modifying this object.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 2.56% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- sun/java system identity manager
- Source
- cve@mitre.org
References
- http://blogs.sun.com/security/entry/sun_alert_253267_sun_javaPatch
- http://secunia.com/advisories/34380Vendor Advisory
- http://securitytracker.com/id?1021881
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-139010-06-1Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1Patch, Vendor Advisory
- http://www.securityfocus.com/bid/34191
- http://www.vupen.com/english/advisories/2009/0797Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49607
- http://blogs.sun.com/security/entry/sun_alert_253267_sun_javaPatch
- http://secunia.com/advisories/34380Vendor Advisory
- http://securitytracker.com/id?1021881
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-139010-06-1Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1Patch, Vendor Advisory
- http://www.securityfocus.com/bid/34191
- http://www.vupen.com/english/advisories/2009/0797Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49607
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.