{"api_version":"1","generated_at":"2026-07-23T14:25:08+00:00","cve":"CVE-2008-5549","urls":{"html":"https://cve.report/CVE-2008-5549","api":"https://cve.report/api/cve/CVE-2008-5549.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-5549","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-5549"},"summary":{"title":"CVE-2008-5549","description":"Unspecified vulnerability in the Sun Java Web Console components in Sun Java System Portal Server 7.1 and 7.2 allows remote attackers to access local files and read the product's configuration information via unknown vectors related to \"access to secure files by ThemeServlet.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2008-12-12 18:30:03","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2008/3408","name":"http://www.vupen.com/english/advisories/2008/3408","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1021380","name":"http://securitytracker.com/id?1021380","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Sun Java System Portal Server Discloses Certain Files to Remote Users - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-243886-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-243886-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-124301-12-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-124301-12-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-138686-01-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-138686-01-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/32770","name":"http://www.securityfocus.com/bid/32770","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Sun Java System Portal Server Web Console Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47256","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47256","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/33120","name":"http://secunia.com/advisories/33120","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Sun Java System Portal Server File Disclosure Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-5549","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-5549","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"5549","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"java_system_portal_server","cpe6":"7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"5549","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"java_system_portal_server","cpe6":"7.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:56:46.619Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"jsps-webconsole-information-disclosure(47256)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47256"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-124301-12-1"},{"name":"ADV-2008-3408","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/3408"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-138686-01-1"},{"name":"33120","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33120"},{"name":"32770","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/32770"},{"name":"243886","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-243886-1"},{"name":"1021380","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1021380"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-12-05T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in the Sun Java Web Console components in Sun Java System Portal Server 7.1 and 7.2 allows remote attackers to access local files and read the product's configuration information via unknown vectors related to \"access to secure files by ThemeServlet.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"jsps-webconsole-information-disclosure(47256)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47256"},{"tags":["x_refsource_CONFIRM"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-124301-12-1"},{"name":"ADV-2008-3408","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/3408"},{"tags":["x_refsource_CONFIRM"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-138686-01-1"},{"name":"33120","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33120"},{"name":"32770","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/32770"},{"name":"243886","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-243886-1"},{"name":"1021380","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1021380"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-5549","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in the Sun Java Web Console components in Sun Java System Portal Server 7.1 and 7.2 allows remote attackers to access local files and read the product's configuration information via unknown vectors related to \"access to secure files by ThemeServlet.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"jsps-webconsole-information-disclosure(47256)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47256"},{"name":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-124301-12-1","refsource":"CONFIRM","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-124301-12-1"},{"name":"ADV-2008-3408","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/3408"},{"name":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-138686-01-1","refsource":"CONFIRM","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-138686-01-1"},{"name":"33120","refsource":"SECUNIA","url":"http://secunia.com/advisories/33120"},{"name":"32770","refsource":"BID","url":"http://www.securityfocus.com/bid/32770"},{"name":"243886","refsource":"SUNALERT","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-243886-1"},{"name":"1021380","refsource":"SECTRACK","url":"http://securitytracker.com/id?1021380"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-5549","datePublished":"2008-12-12T18:13:00.000Z","dateReserved":"2008-12-12T00:00:00.000Z","dateUpdated":"2024-08-07T10:56:46.619Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-12-12 18:30:03","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sun:java_system_portal_server:7.1:*:*:*:*:*:*:*","matchCriteriaId":"A29331A7-9D72-489D-A8DF-5B4C18A19692"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:java_system_portal_server:7.2:*:*:*:*:*:*:*","matchCriteriaId":"83D63923-869B-4156-BBED-DFB417B19420"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"5549","Ordinal":"1","Title":"CVE-2008-5549","CVE":"CVE-2008-5549","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"5549","Ordinal":"1","NoteData":"Unspecified vulnerability in the Sun Java Web Console components in Sun Java System Portal Server 7.1 and 7.2 allows remote attackers to access local files and read the product's configuration information via unknown vectors related to \"access to secure files by ThemeServlet.\"","Type":"Description","Title":"CVE-2008-5549"},{"CveYear":"2008","CveId":"5549","Ordinal":"2","NoteData":"2008-12-12","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"5549","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}