Vulnerabilities > CVE-2007-1419 - Local Unauthorized Access vulnerability in SUN Java Dynamic Management KIT 5.1

047910
CVSS 4.3 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
sun
nessus

Summary

The Java Management Extensions Remote API Remote Method Invocation over Internet Inter-ORB Protocol (JMX RMI-IIOP) API in Java Dynamic Management Kit 5.1 before 20070309 does not properly enforce the java.policy, which allows local users to obtain certain MBeans data access by operating a server application accessed by a privileged remote authenticated user.

Vulnerable Configurations

Part Description Count
Application
Sun
1

Nessus

  • NASL familySolaris Local Security Checks
    NASL idSOLARIS8_119044.NASL
    descriptionJDMK 5.1: patch for Solaris 8 9 10 8_x86 9_x86 10_x86. Date this patch was last updated by Sun : Mar/15/11
    last seen2020-06-01
    modified2020-06-02
    plugin id24853
    published2007-03-18
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/24853
    titleSolaris 8 (sparc) : 119044-04
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_X86_119044.NASL
    descriptionSunOS 5.8 5.9 5.10 5.8_x86 5.9_x86 5.10_x86: JDMK 5.1 patch. Date this patch was last updated by Sun : Mar/15/11
    last seen2018-09-01
    modified2018-08-13
    plugin id24848
    published2007-03-18
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=24848
    titleSolaris 5.10 (x86) : 119044-04
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_124939.NASL
    descriptionVulnerability in the Solaris component of Oracle and Sun Systems Products Suite (subcomponent: Cacao). Supported versions that are affected are 10 and 11.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SNMP. Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Solaris. Vulnerability in the Solaris component of Oracle and Sun Systems Products Suite (subcomponent: Cacao). Supported versions that are affected are 10 and 11.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SNMP. Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Solaris. This plugin has been deprecated and either replaced with individual 124939 patch-revision plugins, or deemed non-security related.
    last seen2019-02-21
    modified2018-07-30
    plugin id24846
    published2007-03-18
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=24846
    titleSolaris 10 (sparc) : 124939-05 (deprecated)
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS9_X86_119044.NASL
    descriptionSunOS 5.8 5.9 5.10 5.8_x86 5.9_x86 5.10_x86: JDMK 5.1 patch. Date this patch was last updated by Sun : Mar/15/11
    last seen2017-10-29
    modified2011-09-18
    plugin id24860
    published2007-03-18
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=24860
    titleSolaris 5.9 (x86) : 119044-04
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS8_X86_119044.NASL
    descriptionSunOS 5.8 5.9 5.10 5.8_x86 5.9_x86 5.10_x86: JDMK 5.1 patch. Date this patch was last updated by Sun : Mar/15/11
    last seen2017-10-29
    modified2011-09-18
    plugin id24855
    published2007-03-18
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=24855
    titleSolaris 5.8 (x86) : 119044-04
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_X86_124939.NASL
    descriptionVulnerability in the Solaris component of Oracle and Sun Systems Products Suite (subcomponent: Cacao). Supported versions that are affected are 10 and 11.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SNMP. Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Solaris. Vulnerability in the Solaris component of Oracle and Sun Systems Products Suite (subcomponent: Cacao). Supported versions that are affected are 10 and 11.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SNMP. Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Solaris. This plugin has been deprecated and either replaced with individual 124939 patch-revision plugins, or deemed non-security related.
    last seen2019-02-21
    modified2018-07-30
    plugin id24850
    published2007-03-18
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=24850
    titleSolaris 10 (x86) : 124939-05 (deprecated)
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS9_119044.NASL
    descriptionSunOS 5.8 5.9 5.10 5.8_x86 5.9_x86 5.10_x86: JDMK 5.1 patch. Date this patch was last updated by Sun : Mar/15/11
    last seen2017-10-29
    modified2011-09-18
    plugin id24857
    published2007-03-18
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=24857
    titleSolaris 5.9 (sparc) : 119044-04
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_119044.NASL
    descriptionSunOS 5.8 5.9 5.10 5.8_x86 5.9_x86 5.10_x86: JDMK 5.1 patch. Date this patch was last updated by Sun : Mar/15/11
    last seen2018-09-01
    modified2018-08-13
    plugin id24844
    published2007-03-18
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=24844
    titleSolaris 5.10 (sparc) : 119044-04