6.8
CVSSv2

CVE-2008-5115

Published: 18/11/2008 Updated: 11/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 up to and including 6.0 SP4, 7.0, and 7.1 allows remote malicious users to hijack the authentication of administrators for requests that update the password via idm/admin/changeself.jsp.

Vulnerable Product Search on Vulmon Subscribe to Product

sun java system identity manager 6.0

sun java system identity manager 7.0

sun java system identity manager 7.1

Exploits

source: wwwsecurityfocuscom/bid/32262/info Sun Java System Identity Manager is prone to multiple web-interface vulnerabilities, including a cross-site request-forgery issue, multiple cross-site scripting issues, multiple HTML-injection issues, and a directory-traversal vulnerability Successful exploits of many of these issues will allo ...