Sun

Java System Identity Manager

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.58%
  • Veröffentlicht 25.03.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the Forgot Password feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

  • EPSS 0.67%
  • Veröffentlicht 25.03.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated administrators and possibly remote attackers to have an unspecified impact by modifying thi...

  • EPSS 1.72%
  • Veröffentlicht 25.03.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Sun Java System Identity Manager (IdM) 7.0 through 8.0 on Linux, AIX, Solaris, and HP-UX permits "control characters" in the passwords of user accounts, which allows remote attackers to execute arbitrary commands via vectors involving "resource adapt...

  • EPSS 1.7%
  • Veröffentlicht 25.03.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Sun Java System Identity Manager (IdM) 7.0 through 8.0 allows remote authenticated users to gain privileges by submitting crafted commands to the Admin Console, as demonstrated by privileges for account creation and other administrative capabilities,...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 25.03.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19595 and 19661.

Exploit
  • EPSS 0.39%
  • Veröffentlicht 25.03.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID 19033.

Exploit
  • EPSS 0.39%
  • Veröffentlicht 25.03.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19659, 19660, and 19683.

Exploit
  • EPSS 0.37%
  • Veröffentlicht 25.03.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying workflows, which allows remote authenticated users to have an unspecified impact.

Exploit
  • EPSS 1.93%
  • Veröffentlicht 25.03.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresChallenge property setting, which allows remote authenticated users to change the passwords of other u...

  • EPSS 0.69%
  • Veröffentlicht 25.03.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the end-user question-based login feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.