CVE-2008-0239
Summary
| CVE | CVE-2008-0239 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-01-11 22:46:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote attackers to inject arbitrary HTML or web script via the (1) cntry or lang parameters to /idm/login.jsp, (2) resultsForm parameter to /idm/account/findForSelect.jsp, or (3) activeControl parameter to /idm/user/main.jsp. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sun | Java System Identity Manager | 6.0 | sp1 | All | All |
| Application | Sun | Java System Identity Manager | 6.0 | sp2 | All | All |
| Application | Sun | Java System Identity Manager | 6.0 | sp3 | All | All |
| Application | Sun | Java System Identity Manager | 7.0 | All | All | All |
| Application | Sun | Java System Identity Manager | 7.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ProCheckUp - Security Vulnerabilities 2007 | af854a3a-2127-422b-91ae-364da2661108 | www.procheckup.com | |
| Sun Java System Identity Manager Cross-Site Scripting Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| ProCheckUp - Security Vulnerabilities 2007 | af854a3a-2127-422b-91ae-364da2661108 | www.procheckup.com | Exploit, Patch |
| Sun Java System Identity Manager Multiple Input Validation Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| #103180: Multiple Security Vulnerabilities in the Sun Java System Identity Manager May Allow HTML Injection, Cross-Site Scripting Exploits or Unauthorized Redirection | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| ProCheckUp - Security Vulnerabilities 2007 | af854a3a-2127-422b-91ae-364da2661108 | www.procheckup.com | Exploit, Patch |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| Several XSS, Cross-domain Redirection and Frame Injection on Sun Java System Identity Manager - SecurityReason.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| SecurityTracker.com Archives - Sun Java System Identity Manager Input Validation Hole Permits Cross-Site Scripting Attacks | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| ProCheckUp - Security Vulnerabilities 2008 | af854a3a-2127-422b-91ae-364da2661108 | www.procheckup.com | Exploit, Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.