First published: Wed Jun 11 2003(Updated: )
The installation of Sun ONE Application Server 7.0 for Windows 2000/XP creates a statefile with world-readable permissions, which allows local users to gain privileges by reading a plaintext password in the statefile.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun ONE Application Server | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2003-0414 is classified as medium due to the risk of local privilege escalation.
To fix CVE-2003-0414, modify the statefile permissions to ensure it is not world-readable.
CVE-2003-0414 can allow local users to read plaintext passwords, potentially leading to unauthorized access.
Only Sun ONE Application Server 7.0 is affected by CVE-2003-0414.
CVE-2003-0414 cannot be exploited remotely as it requires local access to the vulnerable system.