CVE-2009-2713
Summary
| CVE | CVE-2009-2713 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-08-07 19:00:01 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The CDCServlet component in Sun Java System Access Manager 7.0 2005Q4 and 7.1, when Cross Domain Single Sign On (CDSSO) is enabled, does not ensure that "policy advice" is presented to the correct client, which allows remote attackers to obtain sensitive information via unspecified vectors. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sun | Java System Access Manager | 6.3_2005q1 | All | solaris_10_linux | All |
| Application | Sun | Java System Access Manager | 6.3_2005q1 | All | solaris_10_sparc | All |
| Application | Sun | Java System Access Manager | 6.3_2005q1 | All | solaris_10_x86 | All |
| Application | Sun | Java System Access Manager | 6.3_2005q1 | All | solaris_8_linux | All |
| Application | Sun | Java System Access Manager | 6.3_2005q1 | All | solaris_8_sparc | All |
| Application | Sun | Java System Access Manager | 6.3_2005q1 | All | solaris_8_x86 | All |
| Application | Sun | Java System Access Manager | 6.3_2005q1 | All | solaris_9_linux | All |
| Application | Sun | Java System Access Manager | 6.3_2005q1 | All | solaris_9_sparc | All |
| Application | Sun | Java System Access Manager | 6.3_2005q1 | All | solaris_9_x86 | All |
| Application | Sun | Java System Access Manager | 7.0_2005q4 | All | windows | All |
| Application | Sun | Java System Access Manager | 7.1 | All | solaris_10_linux | All |
| Application | Sun | Java System Access Manager | 7.1 | All | solaris_10_sparc | All |
| Application | Sun | Java System Access Manager | 7.1 | All | solaris_10_x86 | All |
| Application | Sun | Java System Access Manager | 7.1 | All | solaris_8_linux | All |
| Application | Sun | Java System Access Manager | 7.1 | All | solaris_8_sparc | All |
| Application | Sun | Java System Access Manager | 7.1 | All | solaris_8_x86 | All |
| Application | Sun | Java System Access Manager | 7.1 | All | solaris_9_linux | All |
| Application | Sun | Java System Access Manager | 7.1 | All | solaris_9_sparc | All |
| Application | Sun | Java System Access Manager | 7.1 | All | solaris_9_x86 | All |
| Application | Sun | Java System Access Manager | 7.1 | All | war | All |
| Application | Sun | Java System Access Manager | 7.1 | All | windows | All |
| Application | Sun | Java System Access Manager | 7_2005q4 | All | solaris_10_linux | All |
| Application | Sun | Java System Access Manager | 7_2005q4 | All | solaris_10_sparc | All |
| Application | Sun | Java System Access Manager | 7_2005q4 | All | solaris_10_x86 | All |
| Application | Sun | Java System Access Manager | 7_2005q4 | All | solaris_8_linux | All |
| Application | Sun | Java System Access Manager | 7_2005q4 | All | solaris_8_sparc | All |
| Application | Sun | Java System Access Manager | 7_2005q4 | All | solaris_8_x86 | All |
| Application | Sun | Java System Access Manager | 7_2005q4 | All | solaris_9_linux | All |
| Application | Sun | Java System Access Manager | 7_2005q4 | All | solaris_9_sparc | All |
| Application | Sun | Java System Access Manager | 7_2005q4 | All | solaris_9_x86 | All |
| Application | Sun | Java System Web Server | 7.0 | All | hp_ux | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Patch |
| Sun Java System Access Manager CDCServlet Component Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Vendor Advisory |
| Sun Java System Access Manager CDCServlet Component Information Disclosure - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.