Show filters
42 Total Results
Displaying 31-40 of 42
Sort by:
Attacker Value
Unknown

CVE-2009-1083

Disclosure Date: March 25, 2009 (last updated October 04, 2023)
Sun Java System Identity Manager (IdM) 7.0 through 8.0 on Linux, AIX, Solaris, and HP-UX permits "control characters" in the passwords of user accounts, which allows remote attackers to execute arbitrary commands via vectors involving "resource adapters."
0
Attacker Value
Unknown

CVE-2009-1078

Disclosure Date: March 25, 2009 (last updated October 04, 2023)
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying workflows, which allows remote authenticated users to have an unspecified impact.
0
Attacker Value
Unknown

CVE-2009-1077

Disclosure Date: March 25, 2009 (last updated October 04, 2023)
The Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresChallenge property setting, which allows remote authenticated users to change the passwords of other users, as demonstrated by changing the administrator's password.
0
Attacker Value
Unknown

CVE-2009-1076

Disclosure Date: March 25, 2009 (last updated October 04, 2023)
Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the end-user question-based login feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
0
Attacker Value
Unknown

CVE-2009-1074

Disclosure Date: March 25, 2009 (last updated October 04, 2023)
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to "ssl termination devices" and lack of support for relative URLs.
0
Attacker Value
Unknown

CVE-2009-1081

Disclosure Date: March 25, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19595 and 19661.
0
Attacker Value
Unknown

CVE-2009-1075

Disclosure Date: March 25, 2009 (last updated October 04, 2023)
Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the Forgot Password feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
0
Attacker Value
Unknown

CVE-2009-1080

Disclosure Date: March 25, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID 19033.
0
Attacker Value
Unknown

CVE-2004-1029

Disclosure Date: March 01, 2005 (last updated February 22, 2025)
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.
0
Attacker Value
Unknown

CVE-2004-0802

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817.
0