Sun Java System Identity Manager Multiple Input Validation Vulnerabilities
BID:27214
Info
Sun Java System Identity Manager Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 27214 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0240 CVE-2008-0241 CVE-2008-0239 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 09 2008 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | Jan Fry and Adrian Pastor of ProCheckUp Ltd discovered these issues. |
| Vulnerable: |
Sun Java System Identity Manager 7.1 Sun Java System Identity Manager 7.0 Sun Java System Identity Manager 6.0 SP3 Sun Java System Identity Manager 6.0 SP2 Sun Java System Identity Manager 6.0 SP1 Sun Java System Identity Manager 6.0 |
| Not Vulnerable: | |
Discussion
Sun Java System Identity Manager Multiple Input Validation Vulnerabilities
Sun Java System Identity Manager is prone to multiple input-validation vulnerabilities, including an HTML-injection issue and cross-site scripting issues, because it fails to adequately sanitize user-supplied input.
Attackers can exploit these issues to execute arbitrary HTML and script code in the context of the affected site. Successful exploits could allow an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
Sun Java System Identity Manager 6.0 SP1, 6.0 SP2, 6.0 SP3, 7.0, and 7.1 are vulnerable.
Sun Java System Identity Manager is prone to multiple input-validation vulnerabilities, including an HTML-injection issue and cross-site scripting issues, because it fails to adequately sanitize user-supplied input.
Attackers can exploit these issues to execute arbitrary HTML and script code in the context of the affected site. Successful exploits could allow an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
Sun Java System Identity Manager 6.0 SP1, 6.0 SP2, 6.0 SP3, 7.0, and 7.1 are vulnerable.
Exploit / POC
Sun Java System Identity Manager Multiple Input Validation Vulnerabilities
An attacker can use a browser to exploit these issues.
To exploit a cross-site scripting issue, the attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
An attacker can use a browser to exploit these issues.
To exploit a cross-site scripting issue, the attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
Solution / Fix
Sun Java System Identity Manager Multiple Input Validation Vulnerabilities
Solution:
Vendor updates are available.
Sun Java System Identity Manager 6.0
Sun Java System Identity Manager 6.0 SP3
Sun Java System Identity Manager 7.1
Sun Java System Identity Manager 7.0
Sun Java System Identity Manager 6.0 SP1
Sun Java System Identity Manager 6.0 SP2
Solution:
Vendor updates are available.
Sun Java System Identity Manager 6.0
Sun Java System Identity Manager 6.0 SP3
Sun Java System Identity Manager 7.1
Sun Java System Identity Manager 7.0
Sun Java System Identity Manager 6.0 SP1
Sun Java System Identity Manager 6.0 SP2
References
Sun Java System Identity Manager Multiple Input Validation Vulnerabilities
References:
References:
- Identity Management Solutions (Sun)
- PR07-06, PR07-07, PR07-08, PR07-09, PR07-10, PR07-12: Several XSS, Cross-domain (ProCheckUp Research
) - Sun Alert ID: 103180 (Sun)