Skip to main content

Vendor/product archive

sun / java_system_access_manager CVEs

Beta · best-effort

16 CVEs tagged to sun / java_system_access_manager2 Critical, 3 High, 8 Medium, 3 Low, 0 Unrated.

CVE-2010-4444

Published Jan 19, 2011

Unspecified vulnerability in Oracle Sun Java System Access Manager and Oracle OpenSSO 7, 7.1, and 8 allows remote attackers to affect confidentiality, integrity, and availability…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2268

Published Jul 1, 2009

Cross-site scripting (XSS) vulnerability in the Cross-Domain Controller (CDC) servlet in Sun Java System Access Manager 6 2005Q1, 7 2005Q4, and 7.1 allows remote attackers to inje…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-0348

Published Jan 29, 2009

The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7.1 responds differently to a failed login attempt depending on whether the user acc…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0170

Published Jan 16, 2009

Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1 allows remote authenticated users with console privileges to discover passwords, and obtain unspecified other "access…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0169

Published Jan 16, 2009

Sun Java System Access Manager 7.1 allows remote authenticated sub-realm administrators to gain privileges, as demonstrated by creating the amadmin account in the sub-realm, and t…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2705

Published Jun 16, 2008

Unspecified vulnerability in Sun Java System Access Manager (AM) 7.1, when used with certain versions and configurations of Sun Directory Server Enterprise Edition (DSEE), allows…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-1204

Published Mar 8, 2008

Multiple cross-site scripting (XSS) vulnerabilities in the Administration Console in Sun Java System Access Manager 7.1 and 7 2005Q4 allow remote attackers to inject arbitrary web…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3700

Published Jul 11, 2007

Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is configured in the com.iplanet.services.debug.level property…

CVSS 1.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0628

Published Jan 31, 2007

Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Access Manager 6.1, 6.2, 6 2005Q1 (6.3), and 7 2005Q4 (7.0) before 20070129 allow remote attackers to inject…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0531

Published Feb 4, 2006

Unspecified vulnerability in Sun Java System Access Manager 7.0 allows local users logged in as "root" to bypass authentication and gain top-level administrator privileges via the…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1