CVE-2007-5152

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
01/10/2007
Last modified:
09/04/2025

Description

Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container restart, which allows remote attackers to perform administrative tasks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sun:java_system_access_manager:7.1:*:hp-ux:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7.1:*:linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_x86:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7.1:*:windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:9.1:*:*:*:*:*:*:*