CVE-2009-2445
Summary
| CVE | CVE-2009-2445 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-07-13 17:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Oracle iPlanet Web Server (formerly Sun Java System Web Server or Sun ONE Web Server) 6.1 before SP12, and 7.0 through Update 6, when running on Windows, allows remote attackers to read arbitrary JSP files via an alternate data stream syntax, as demonstrated by a .jsp::$DATA URI. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sun | Java System Web Server | 6.1 | All | windows | All |
| Application | Sun | Java System Web Server | 6.1 | sp10 | windows | All |
| Application | Sun | Java System Web Server | 6.1 | sp11 | windows | All |
| Application | Sun | Java System Web Server | 6.1 | sp4 | windows | All |
| Application | Sun | Java System Web Server | 6.1 | sp5 | windows | All |
| Application | Sun | Java System Web Server | 6.1 | sp6 | windows | All |
| Application | Sun | Java System Web Server | 6.1 | sp7 | windows | All |
| Application | Sun | Java System Web Server | 6.1 | sp8 | windows | All |
| Application | Sun | Java System Web Server | 6.1 | sp9 | windows | All |
| Application | Sun | Java System Web Server | 7.0 | update_5 | windows | All |
| Application | Sun | Java System Web Server | 7.0 | update_6 | windows | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Sun Java System Web Server Java Server Pages Content Disclosure - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Page not found – Iso Warez | af854a3a-2127-422b-91ae-364da2661108 | isowarez.de | Exploit |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Vendor Advisory |
| Sun Java System Web Server Discloses JSP Source Code to Remote Users - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Exploit |
| jvndb.jvn.jp/jvndb/JVNDB-2009-002069 | af854a3a-2127-422b-91ae-364da2661108 | jvndb.jvn.jp | |
| www.osvdb.org/55655 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| JVN#47124169: Oracle iPlanet Web Server information disclosure vulnerability | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.