Sun Java System Access Manager Local Authentication Bypass Vulnerability
BID:16474
Info
Sun Java System Access Manager Local Authentication Bypass Vulnerability
| Bugtraq ID: | 16474 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 02 2006 12:00AM |
| Updated: | Feb 07 2006 08:55PM |
| Credit: | This issue was disclosed in the referenced Sun alert. |
| Vulnerable: |
Sun Java System Access Manager 7.0 2005Q4 Solaris x Sun Java System Access Manager 7.0 2005Q4 Solaris S Sun Java System Access Manager 7.0 2005Q4 Linux |
| Not Vulnerable: | |
Discussion
Sun Java System Access Manager Local Authentication Bypass Vulnerability
Sun Java System Access Manager is susceptible to a local authentication-bypass vulnerability. This issue is due to the application's failure to require proper credentials before allowing local users to administer the application.
This issue allows local users with superuser access on affected computers to administer the Access Manager installation as a top-level administrator. Further attacks (such as gaining access to services that use the Access Manager software as its authorization source) are possible.
Sun Java System Access Manager is susceptible to a local authentication-bypass vulnerability. This issue is due to the application's failure to require proper credentials before allowing local users to administer the application.
This issue allows local users with superuser access on affected computers to administer the Access Manager installation as a top-level administrator. Further attacks (such as gaining access to services that use the Access Manager software as its authorization source) are possible.
Exploit / POC
Sun Java System Access Manager Local Authentication Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Sun Java System Access Manager Local Authentication Bypass Vulnerability
Solution:
The vendor has released Sun Alert ID 102140, along with patches to address this issue. Please see the referenced advisory for further information.
Sun Java System Access Manager 7.0 2005Q4 Solaris x
Sun Java System Access Manager 7.0 2005Q4 Linux
Sun Java System Access Manager 7.0 2005Q4 Solaris S
Solution:
The vendor has released Sun Alert ID 102140, along with patches to address this issue. Please see the referenced advisory for further information.
Sun Java System Access Manager 7.0 2005Q4 Solaris x
Sun Java System Access Manager 7.0 2005Q4 Linux
Sun Java System Access Manager 7.0 2005Q4 Solaris S
References
Sun Java System Access Manager Local Authentication Bypass Vulnerability
References:
References: