CVE-2009-1077
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
25/03/2009
Last modified:
09/04/2025
Description
The Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresChallenge property setting, which allows remote authenticated users to change the passwords of other users, as demonstrated by changing the administrator's password.
Impact
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:sun:java_system_identity_manager:7.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:sun:java_system_identity_manager:7.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:sun:java_system_identity_manager:7.1.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:sun:java_system_identity_manager:8.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://blogs.sun.com/security/entry/sun_alert_253267_sun_java
- http://secunia.com/advisories/34380
- http://securitytracker.com/id?1021881=
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-137621-11-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-139010-06-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-140936-01-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1
- http://www.securityfocus.com/bid/34191
- http://www.vupen.com/english/advisories/2009/0797
- http://blogs.sun.com/security/entry/sun_alert_253267_sun_java
- http://secunia.com/advisories/34380
- http://securitytracker.com/id?1021881=
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-137621-11-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-139010-06-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-140936-01-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1
- http://www.securityfocus.com/bid/34191
- http://www.vupen.com/english/advisories/2009/0797