Sun Java ASP Server Remote Authentication Bypass Vulnerability
BID:29539
Info
Sun Java ASP Server Remote Authentication Bypass Vulnerability
| Bugtraq ID: | 29539 |
| Class: | Design Error |
| CVE: |
CVE-2008-2406 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 04 2008 12:00AM |
| Updated: | Jun 04 2008 12:00AM |
| Credit: | anonymous |
| Vulnerable: |
Sun Java System Active Server Pages (ASP) Server 4.0.2 Sun Java System Active Server Pages (ASP) Server 4.0.1 Sun Java System Active Server Pages (ASP) Server 4.0 |
| Not Vulnerable: |
Sun Java System Active Server Pages (ASP) Server 4.0.3 |
Discussion
Sun Java ASP Server Remote Authentication Bypass Vulnerability
Sun Java ASP Server is prone to a remote authentication-bypass vulnerability because of a design error in the ASP application server.
Successfully exploiting this issue will allow attackers to gain unauthorized access to the affected application.
Versions prior to Sun Java ASP Server 4.0.3 are vulnerable.
Sun Java ASP Server is prone to a remote authentication-bypass vulnerability because of a design error in the ASP application server.
Successfully exploiting this issue will allow attackers to gain unauthorized access to the affected application.
Versions prior to Sun Java ASP Server 4.0.3 are vulnerable.
Exploit / POC
Sun Java ASP Server Remote Authentication Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Sun Java ASP Server Remote Authentication Bypass Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
References
Sun Java ASP Server Remote Authentication Bypass Vulnerability
References:
References:
- Java System Active Server Pages Homepage (Sun)
- Sun Java System Active Server Pages Authorization Bypass Vulnerability (iDefense Labs)
- iDefense Security Advisory 06.03.08: Sun Java System ASP Authorization (iDefense Labs
) - Multiple Security Vulnerabilities in Sun Java ASP Server may lead to execution o (Sun)