First published: Mon Jun 01 2009(Updated: )
The PointBase 4.6 database component in the J2EE 1.4 reference implementation (J2EE/RI) allows remote attackers to execute arbitrary programs, conduct a denial of service, and obtain sensitive information via a crafted SQL statement, related to "inadequate security settings and library bugs in sun.* and org.apache.* packages."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun J2ee | =1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1573 is considered critical due to its potential for remote code execution and denial of service.
To fix CVE-2003-1573, it is recommended to update to a patched version of the J2EE reference implementation or switch to a more secure database component.
CVE-2003-1573 affects the J2EE 1.4 reference implementation, specifically version 1.4.
Yes, CVE-2003-1573 allows remote attackers to execute crafted SQL commands, potentially exposing sensitive information.
Temporary workarounds include restricting network access to the J2EE application and disabling the vulnerable database component if possible.