Sun Java System Calendar Server Authentication Proxy Privilege Escalation Vulnerability
BID:10788
Info
Sun Java System Calendar Server Authentication Proxy Privilege Escalation Vulnerability
| Bugtraq ID: | 10788 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2004 12:00AM |
| Updated: | Jul 23 2004 12:00AM |
| Credit: | The individual responsible for the discovery of this issue is currently unknown; the vendor disclosed this issue. |
| Vulnerable: |
Sun Java System Calendar Server 6.2 x86 Sun Java System Calendar Server 6.2 |
| Not Vulnerable: | |
Discussion
Sun Java System Calendar Server Authentication Proxy Privilege Escalation Vulnerability
It has been reported that Sun Java System Portal Server is affected by a privilege escalation vulnerability in the calendar server when an authentication proxy is used. This issue is due to a failure of the application to validate access credentials.
This issue will allow an attacker to gain administrator access to the affected calendar server, allowing them to create, modify and delete users as well as calendar information. Other attacks are also possible.
It has been reported that Sun Java System Portal Server is affected by a privilege escalation vulnerability in the calendar server when an authentication proxy is used. This issue is due to a failure of the application to validate access credentials.
This issue will allow an attacker to gain administrator access to the affected calendar server, allowing them to create, modify and delete users as well as calendar information. Other attacks are also possible.
Exploit / POC
Sun Java System Calendar Server Authentication Proxy Privilege Escalation Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Sun Java System Calendar Server Authentication Proxy Privilege Escalation Vulnerability
Solution:
The vendor has released patches dealing with this issue.
Sun Java System Calendar Server 6.2 x86
Sun Java System Calendar Server 6.2
Solution:
The vendor has released patches dealing with this issue.
Sun Java System Calendar Server 6.2 x86
Sun Java System Calendar Server 6.2
References
Sun Java System Calendar Server Authentication Proxy Privilege Escalation Vulnerability
References:
References: