5
CVE-2009-0348
- EPSS 8.47%
- Veröffentlicht 29.01.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7.1 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sun ≫ Java System Access Manager Version6.3_2005q1 Editionsolaris_10_linux
Sun ≫ Java System Access Manager Version6.3_2005q1 Editionsolaris_10_sparc
Sun ≫ Java System Access Manager Version6.3_2005q1 Editionsolaris_10_windows
Sun ≫ Java System Access Manager Version6.3_2005q1 Editionsolaris_10_x86
Sun ≫ Java System Access Manager Version6.3_2005q1 Editionsolaris_8_linux
Sun ≫ Java System Access Manager Version6.3_2005q1 Editionsolaris_8_sparc
Sun ≫ Java System Access Manager Version6.3_2005q1 Editionsolaris_8_windows
Sun ≫ Java System Access Manager Version6.3_2005q1 Editionsolaris_8_x86
Sun ≫ Java System Access Manager Version6.3_2005q1 Editionsolaris_9_linux
Sun ≫ Java System Access Manager Version6.3_2005q1 Editionsolaris_9_sparc
Sun ≫ Java System Access Manager Version6.3_2005q1 Editionsolaris_9_windows
Sun ≫ Java System Access Manager Version6.3_2005q1 Editionsolaris_9_x86
Sun ≫ Java System Access Manager Version7.1 Editionsolaris_10_linux
Sun ≫ Java System Access Manager Version7.1 Editionsolaris_10_sparc
Sun ≫ Java System Access Manager Version7.1 Editionsolaris_10_windows
Sun ≫ Java System Access Manager Version7.1 Editionsolaris_10_x86
Sun ≫ Java System Access Manager Version7.1 Editionsolaris_8_linux
Sun ≫ Java System Access Manager Version7.1 Editionsolaris_8_sparc
Sun ≫ Java System Access Manager Version7.1 Editionsolaris_8_windows
Sun ≫ Java System Access Manager Version7.1 Editionsolaris_8_x86
Sun ≫ Java System Access Manager Version7.1 Editionsolaris_9_linux
Sun ≫ Java System Access Manager Version7.1 Editionsolaris_9_sparc
Sun ≫ Java System Access Manager Version7.1 Editionsolaris_9_windows
Sun ≫ Java System Access Manager Version7.1 Editionsolaris_9_x86
Sun ≫ Java System Access Manager Version7_2005q4 Editionsolaris_10_linux
Sun ≫ Java System Access Manager Version7_2005q4 Editionsolaris_10_sparc
Sun ≫ Java System Access Manager Version7_2005q4 Editionsolaris_10_windows
Sun ≫ Java System Access Manager Version7_2005q4 Editionsolaris_10_x86
Sun ≫ Java System Access Manager Version7_2005q4 Editionsolaris_8_linux
Sun ≫ Java System Access Manager Version7_2005q4 Editionsolaris_8_sparc
Sun ≫ Java System Access Manager Version7_2005q4 Editionsolaris_8_windows
Sun ≫ Java System Access Manager Version7_2005q4 Editionsolaris_8_x86
Sun ≫ Java System Access Manager Version7_2005q4 Editionsolaris_9_linux
Sun ≫ Java System Access Manager Version7_2005q4 Editionsolaris_9_sparc
Sun ≫ Java System Access Manager Version7_2005q4 Editionsolaris_9_windows
Sun ≫ Java System Access Manager Version7_2005q4 Editionsolaris_9_x86
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 8.47% | 0.915 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.