Sun ONE Application Server Plaintext Password Vulnerability
BID:7712
Info
Sun ONE Application Server Plaintext Password Vulnerability
| Bugtraq ID: | 7712 |
| Class: | Design Error |
| CVE: |
CVE-2003-0414 |
| Remote: | No |
| Local: | Yes |
| Published: | May 27 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery of this vulnerability has been credited to "SPI Labs" <[email protected]>. |
| Vulnerable: |
Sun ONE Application Server 7.0 Standard Edition Sun ONE Application Server 7.0 Platform Edition |
| Not Vulnerable: | |
Discussion
Sun ONE Application Server Plaintext Password Vulnerability
A problem with the Sun ONE Application Server could make unauthorized access to credentials possible.
It has been reported that a problem exists in the method used for the storage of passwords by Sun ONE Application Server. This could lead to local users gaining unauthorized access to passwords, and potentially unauthorized access to the Sun ONE administrative server.
It should be noted that although this vulnerability has been reported to affect Sun ONE Application Server version 7.0 on Windows platforms, previous versions might also be affected.
A problem with the Sun ONE Application Server could make unauthorized access to credentials possible.
It has been reported that a problem exists in the method used for the storage of passwords by Sun ONE Application Server. This could lead to local users gaining unauthorized access to passwords, and potentially unauthorized access to the Sun ONE administrative server.
It should be noted that although this vulnerability has been reported to affect Sun ONE Application Server version 7.0 on Windows platforms, previous versions might also be affected.
Exploit / POC
Sun ONE Application Server Plaintext Password Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Sun ONE Application Server Plaintext Password Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Sun ONE Application Server Plaintext Password Vulnerability
References:
References:
- Multiple Vulnerabilities in Sun-One Application Server (SPI Dynamics)
- Sun Alert ID: 55221 (Sun)
- Sun ONE Application Server Homepage (Sun)
- Multiple Vulnerabilities in Sun-One Application Server ("SPI Labs"
)