CVE-2009-0169
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
16/01/2009
Last modified:
09/04/2025
Description
Sun Java System Access Manager 7.1 allows remote authenticated sub-realm administrators to gain privileges, as demonstrated by creating the amadmin account in the sub-realm, and then logging in as amadmin in the root realm.
Impact
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:sun:java_system_access_manager:7.1:*:linux:*:*:*:*:* | ||
cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_sparc:*:*:*:*:* | ||
cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_x86:*:*:*:*:* | ||
cpe:2.3:a:sun:java_system_access_manager:7.1:*:windows:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-02-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-249106-1
- http://www.securityfocus.com/bid/33266
- http://www.securitytracker.com/id?1021604=
- http://www.vupen.com/english/advisories/2009/0157
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47944
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-02-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-249106-1
- http://www.securityfocus.com/bid/33266
- http://www.securitytracker.com/id?1021604=
- http://www.vupen.com/english/advisories/2009/0157
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47944