Vulnerabilities > SUN > Java System Identity Manager > 7.0

DATE CVE VULNERABILITY TITLE RISK
2009-03-25 CVE-2009-1074 Cryptographic Issues vulnerability in SUN Java System Identity Manager
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to "ssl termination devices" and lack of support for relative URLs.
network
low complexity
sun CWE-310
5.0
2008-11-18 CVE-2008-5118 Multiple vulnerability in SUN Java System Identity Manager 6.0/7.0/7.1
Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via unspecified vectors, related to "frame injection."
network
sun
4.3
2008-11-18 CVE-2008-5117 Improper Input Validation vulnerability in SUN Java System Identity Manager 6.0/7.0/7.1
Open redirect vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
low complexity
sun CWE-20
6.4
2008-11-18 CVE-2008-5116 Path Traversal vulnerability in SUN Java System Identity Manager 6.0/7.0/7.1
Directory traversal vulnerability in idm/includes/helpServer.jsp in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to read arbitrary files in the filesystem of the IDM server via directory traversal sequences in the ext parameter.
network
low complexity
sun CWE-22
7.8
2008-11-18 CVE-2008-5115 Cross-Site Request Forgery (CSRF) vulnerability in SUN Java System Identity Manager 6.0/7.0/7.1
Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hijack the authentication of administrators for requests that update the password via idm/admin/changeself.jsp.
network
sun CWE-352
6.8
2008-11-18 CVE-2008-5114 Cross-Site Scripting vulnerability in SUN Java System Identity Manager 6.0/7.0/7.1
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
sun CWE-79
4.3
2008-01-11 CVE-2008-0241 Improper Input Validation vulnerability in SUN Java System Identity Manager 6.0/7.0/7.1
Open redirect vulnerability in /idm/user/login.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the nextPage parameter.
network
sun CWE-20
5.8
2008-01-11 CVE-2008-0240 Cross-Site Scripting vulnerability in SUN Java System Identity Manager 6.0/7.0/7.1
/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."
network
sun CWE-79
4.3
2008-01-11 CVE-2008-0239 Cross-Site Scripting vulnerability in SUN Java System Identity Manager 6.0/7.0/7.1
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote attackers to inject arbitrary HTML or web script via the (1) cntry or lang parameters to /idm/login.jsp, (2) resultsForm parameter to /idm/account/findForSelect.jsp, or (3) activeControl parameter to /idm/user/main.jsp.
network
sun CWE-79
4.3