Executive Summary

Title Sun Alert 255968 Security Vulnerability in Sun Java System Access Manager May Provide Security Information to the Wrong Client
Name SUN-255968 First vendor Publication 2009-08-05
Vendor Sun Last vendor Modification 2010-01-04
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:N/A:N)
Cvss Base Score 4.3 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores


Product: Sun Java System Access Manager 7.1
State: Resolved
First released: 05-Aug-2009

Original Source

Url : http://blogs.sun.com/security/entry/sun_alert_255968_security_vulnerability

CPE : Common Platform Enumeration

Application 30
Application 1

OpenVAS Exploits

Date Description
2009-08-26 Name : Sun Java System Access Manager Information Disclosure vulnerability
File : nvt/secpod_sjs_access_manager_info_disc_vuln.nasl
2009-08-26 Name : Sun JS Access Manager And OpenSSO Information Disclosure vulnerability
File : nvt/secpod_sjs_am_n_opensso_info_disc_vuln.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
56816 Sun Java System Access Manager CDCServlet Component CDSSO Unspecified Informa...

Java System Access Manager contains a flaw that may lead to an unauthorized information disclosure.  The issue is triggered when unspecified issue occurs, which will disclose policy advice information to the wrong client resulting in a loss of confidentiality.

Nessus® Vulnerability Scanner

Date Description
2009-04-23 Name : The remote host is missing Sun Security Patch number 120954-12
File : solaris10_120954.nasl - Type : ACT_GATHER_INFO
2009-04-23 Name : The remote host is missing Sun Security Patch number 120955-12
File : solaris10_x86_120955.nasl - Type : ACT_GATHER_INFO
2009-04-23 Name : The remote host is missing Sun Security Patch number 120954-12
File : solaris8_120954.nasl - Type : ACT_GATHER_INFO
2009-04-23 Name : The remote host is missing Sun Security Patch number 120954-12
File : solaris9_120954.nasl - Type : ACT_GATHER_INFO
2009-04-23 Name : The remote host is missing Sun Security Patch number 120955-12
File : solaris9_x86_120955.nasl - Type : ACT_GATHER_INFO