Show filters
27 Total Results
Displaying 11-20 of 27
Sort by:
Attacker Value
Unknown
CVE-2008-2120
Disclosure Date: May 09, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Sun Java System Application Server 7 2004Q2 before Update 6, Web Server 6.1 before SP8, and Web Server 7.0 before Update 1 allows remote attackers to obtain source code of JSP files via unknown vectors.
0
Attacker Value
Unknown
CVE-2007-5152
Disclosure Date: October 01, 2007 (last updated October 04, 2023)
Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container restart, which allows remote attackers to perform administrative tasks.
0
Attacker Value
Unknown
CVE-2007-5153
Disclosure Date: October 01, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 8.x container, allows remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-4511
Disclosure Date: August 23, 2007 (last updated October 04, 2023)
The Sun Admin Console in Sun Application Server 9.0_0.1 does not apply certain configuration changes persistently, which causes the (1) SSL and (2) SSL_MutualAuth ORB listener services to enable all protocols and ciphers after the services are restarted, possibly allowing remote attackers to bypass intended policy.
0
Attacker Value
Unknown
CVE-2007-4025
Disclosure Date: July 26, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Sun Java System (SJS) Application Server 8.1 through 9.0 before 20070724 on Windows allows remote attackers to obtain JSP source code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-3715
Disclosure Date: July 11, 2007 (last updated October 04, 2023)
Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.
0
Attacker Value
Unknown
CVE-2006-6276
Disclosure Date: December 04, 2006 (last updated February 09, 2024)
HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypass HTTP request filtering, hijack web sessions, perform cross-site scripting (XSS), and poison web caches via unspecified attack vectors.
0
Attacker Value
Unknown
CVE-2006-5654
Disclosure Date: November 03, 2006 (last updated October 04, 2023)
Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6.0 before SP 10 and ONE Application Server 7 before Update 3, when SSLv2 is enabled, allows remote authenticated users to cause a denial of service (application crash) via unspecified vectors. NOTE: due to lack of details from the vendor, it is unclear whether this is related to vector 1 in CVE-2006-5201 or CVE-2006-3127.
0
Attacker Value
Unknown
CVE-2006-3921
Disclosure Date: July 28, 2006 (last updated October 04, 2023)
Sun Java System Application Server (SJSAS) 7 through 8.1 and Web Server (SJSWS) 6.0 and 6.1 allows remote authenticated users to read files outside of the "document root directory" via a direct request using a UTF-8 encoded URI.
0
Attacker Value
Unknown
CVE-2006-3225
Disclosure Date: June 26, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Sun ONE Application Server 7 before Update 9, Java System Application Server 7 2004Q2 before Update 5, and Java System Application Server Enterprise Edition 8.1 2005 Q1 allows remote attackers to inject arbitrary HTML or web script via unknown vectors.
0