漏洞信息详情
Sun Java System Access Manager 信息泄露漏洞
- CNNVD编号:CNNVD-200901-212
- 危害等级: 低危
- CVE编号: CVE-2009-0170
- 漏洞类型: 信任管理
- 发布时间: 2009-01-16
- 威胁类型: 远程
- 更新时间: 2009-02-05
- 厂 商: sun
- 漏洞来源: The vendor disclos...
漏洞简介
Sun Java System Access Manager 6.3 2005Q1,7 2005Q4和7.1版本允许拥有控制台特权的远程认证用户通过访问控制台中的配置项组件,来发现密码和获得其他未明的\"对资源的访问权限\"。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接: Sun Java System Access Manager 7.0 2005Q4 Windows Sun 124296-08 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -124296-08-1 Sun Java System Access Manager 7.1 Solaris SPARC Sun 126356-02 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -126356-02-1 Sun Java System Access Manager 7.0 2005Q4 Solaris S Sun 120954-08 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -120954-08-1 Sun Java System Access Manager 6.3 2005Q1 SPARC Sun 119465-15 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -119465-15-1 Sun Java System Access Manager 7.0 2005Q4 HP-UX Sun 126371-08 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -126371-08-1 Sun Java System Access Manager 6.3 2005Q1 Linux Sun 119502-15 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -119502-15-1 Sun Java System Access Manager 7.1 Linux Sun 126358-02 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -126358-02-1 Sun Java System Access Manager 7.0 2005Q4 Solaris x Sun 120955-08 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -120955-08-1 Sun Java System Access Manager 7.0 2005Q4 Linux Sun 120956-08 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -120956-08-1 Sun Java System Access Manager 7.1 Windows Sun 126359-02 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -126359-02-1 Sun Java System Access Manager 7.1 Solaris x86 Sun 126357-02 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -126357-02-1
参考网址
来源: BID 名称: 33265 链接:http://www.securityfocus.com/bid/33265 来源: SUNALERT 名称: 242166 链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-242166-1 来源: sunsolve.sun.com 链接:http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-02-1 来源: XF 名称: sun-jsam-password-info-disclosure(47942) 链接:http://xforce.iss.net/xforce/xfdb/47942 来源: SECTRACK 名称: 1021605 链接:http://www.securitytracker.com/id?1021605 来源: VUPEN 名称: ADV-2009-0156 链接:http://www.frsirt.com/english/advisories/2009/0156
受影响实体
- Sun Java_system_access_manager:7.0_2005q4
- Sun Java_system_access_manager:6.3_2005q4
- Sun Java_system_access_manager:7.1
- Sun Java_system_access_manager:6.3
补丁
暂无
评论