Sun Java System Portal Server Multiple Unspecified Cross Site Scripting Vulnerabilities
BID:37186
Info
Sun Java System Portal Server Multiple Unspecified Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 37186 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 02 2009 12:00AM |
| Updated: | Dec 02 2009 05:55PM |
| Credit: | Sun |
| Vulnerable: |
Sun Java System Portal Server 6.3.1 Sun Java System Portal Server 7.2 Sun Java System Portal Server 7.1 |
| Not Vulnerable: | |
Discussion
Sun Java System Portal Server Multiple Unspecified Cross Site Scripting Vulnerabilities
Sun Java System Portal Server is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Java System Portal Server 6.3.1, 7.1, and 7.2 are vulnerable.
Sun Java System Portal Server is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Java System Portal Server 6.3.1, 7.1, and 7.2 are vulnerable.
Exploit / POC
Sun Java System Portal Server Multiple Unspecified Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Sun Java System Portal Server Multiple Unspecified Cross Site Scripting Vulnerabilities
Solution:
The vendor has released updates. Please see the references for details.
Sun Java System Portal Server 7.2
Sun Java System Portal Server 7.1
Sun Java System Portal Server 6.3.1
Solution:
The vendor has released updates. Please see the references for details.
Sun Java System Portal Server 7.2
-
Sun 138686-04
for SPARC
http://sunsolve.sun.com/pdownload.do?target=138686-04&method=h -
Sun 138687-04
for x86
http://sunsolve.sun.com/pdownload.do?target=138687-04&method=h -
Sun 138688-04
for Linux
http://sunsolve.sun.com/pdownload.do?target=138688-04&method=h
Sun Java System Portal Server 7.1
-
Sun 124301-14
for SPARC
http://sunsolve.sun.com/pdownload.do?target=124301-14&method=h -
Sun 124302-14
for x86
http://sunsolve.sun.com/pdownload.do?target=124302-14&method=h -
Sun 124303-14
for Linux
http://sunsolve.sun.com/pdownload.do?target=124303-14&method=h
Sun Java System Portal Server 6.3.1
-
Sun 118950-39
for SPARC
http://sunsolve.sun.com/pdownload.do?target=118950-39&method=h -
Sun 118951-39
for x86
http://sunsolve.sun.com/pdownload.do?target=118951-39&method=h -
Sun 118952-39
for Linux
http://sunsolve.sun.com/pdownload.do?target=118952-39&method=h
References
Sun Java System Portal Server Multiple Unspecified Cross Site Scripting Vulnerabilities
References:
References:
- Cross-Site Scripting (XSS) Vulnerabilities in Sun Java System Portal Server's Ga (Sun)
- Sun Homepage (Sun Microsystems )