CVE-2009-1082
https://notcve.org/view.php?id=CVE-2009-1082
Sun Java System Identity Manager (IdM) 7.0 through 8.0 allows remote authenticated users to gain privileges by submitting crafted commands to the Admin Console, as demonstrated by privileges for account creation and other administrative capabilities, related to the saveNoValidate action and saveNoValidateAllowedFormsAndWorkflows IDs. Sun Java System Identity Manager (IdM) v7.0 hasta v8.0, permite a usuarios autenticados en remoto ganar privilegios al enviar comandos manipulados a la Consola Admin, como se ha demostrado a través de privilegios para crear cuentas y otras capacidades administrativas. Está relacionado con la acción saveNoValidate e IDs saveNoValidateAllowedFormsAndWorkflows. • http://blogs.sun.com/security/entry/sun_alert_253267_sun_java http://secunia.com/advisories/34380 http://securitytracker.com/id?1021881 http://sunsolve.sun.com/search/document.do?assetkey=1-21-137621-11-1 http://sunsolve.sun.com/search/document.do?assetkey=1-21-139010-06-1 http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1 http://sunsolve.sun.com/search/document.do? • CWE-20: Improper Input Validation •
CVE-2009-1081
https://notcve.org/view.php?id=CVE-2009-1081
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19595 and 19661. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Sun Java System Identity Manager (IdM) v7.0 a v8.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de vectores sin especificar, también conocido como Bug IDs 19595 y 19661. • http://blogs.sun.com/security/entry/sun_alert_253267_sun_java http://secunia.com/advisories/34380 http://securitytracker.com/id?1021881 http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1 http://www.securityfocus.com/bid/34191 http://www.vupen.com/english/advisories/2009/0797 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2009-1075
https://notcve.org/view.php?id=CVE-2009-1075
Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the Forgot Password feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. Sun Java System Identity Manager (IdM) v7.0 hasta v8.0 responde diferente a fallos de la característica del "Olvido de Contraseña" dependiendo de si la cuenta de usuario existe, lo que permite a los atacantes remotos enumerar nombres de usuario válidos. • http://blogs.sun.com/security/entry/sun_alert_253267_sun_java http://secunia.com/advisories/34380 http://securitytracker.com/id?1021881 http://sunsolve.sun.com/search/document.do?assetkey=1-21-140936-01-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1 http://www.securityfocus.com/bid/34191 http://www.vupen.com/english/advisories/2009/0797 • CWE-255: Credentials Management Errors •
CVE-2009-1078
https://notcve.org/view.php?id=CVE-2009-1078
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying workflows, which allows remote authenticated users to have an unspecified impact. Sun Java System Identity Manager (IdM) v7.0 a la v8.0 no impone los requisitos de privilegios esperados para (1) la eliminación de las políticas de auditoría (2) la modificación de flujos de trabajo, lo que permite a usuarios autenticados remotamente tener un impacto sin especificar. • http://blogs.sun.com/security/entry/sun_alert_253267_sun_java http://secunia.com/advisories/34380 http://securitytracker.com/id?1021881 http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1 http://www.securityfocus.com/bid/34191 http://www.vupen.com/english/advisories/2009/0797 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2009-1079
https://notcve.org/view.php?id=CVE-2009-1079
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19659, 19660, and 19683. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Sun Java System Identity Manager (IdM) v7.0 hasta v8.0 permite a atacantes remotos inyectar web script o HTML a través de vectores no especificados, también conocido como Bug IDs 19659, 19660, y 19683. • http://blogs.sun.com/security/entry/sun_alert_253267_sun_java http://secunia.com/advisories/34380 http://securitytracker.com/id?1021881 http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1 http://www.securityfocus.com/bid/34191 http://www.vupen.com/english/advisories/2009/0797 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •