Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2009-2713 | First vendor Publication | 2009-08-07 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The CDCServlet component in Sun Java System Access Manager 7.0 2005Q4 and 7.1, when Cross Domain Single Sign On (CDSSO) is enabled, does not ensure that "policy advice" is presented to the correct client, which allows remote attackers to obtain sensitive information via unspecified vectors. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2713 |
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2009-08-26 | Name : Sun Java System Access Manager Information Disclosure vulnerability File : nvt/secpod_sjs_access_manager_info_disc_vuln.nasl |
2009-08-26 | Name : Sun JS Access Manager And OpenSSO Information Disclosure vulnerability File : nvt/secpod_sjs_am_n_opensso_info_disc_vuln.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
56816 | Sun Java System Access Manager CDCServlet Component CDSSO Unspecified Informa... Java System Access Manager contains a flaw that may lead to an unauthorized information disclosure. Â The issue is triggered when unspecified issue occurs, which will disclose policy advice information to the wrong client resulting in a loss of confidentiality. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2009-04-23 | Name : The remote host is missing Sun Security Patch number 120954-12 File : solaris10_120954.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote host is missing Sun Security Patch number 120955-12 File : solaris10_x86_120955.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote host is missing Sun Security Patch number 120954-12 File : solaris8_120954.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote host is missing Sun Security Patch number 120954-12 File : solaris9_120954.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote host is missing Sun Security Patch number 120955-12 File : solaris9_x86_120955.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:10:43 |
|
2024-11-28 12:19:32 |
|
2021-05-04 12:09:55 |
|
2021-04-22 01:10:17 |
|
2020-05-23 00:24:08 |
|
2016-04-26 19:01:15 |
|
2014-02-17 10:51:05 |
|
2013-05-10 23:55:14 |
|