First published: Fri May 14 2004(Updated: )
The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inaccessible, which could allow remote attackers to obtain sensitive information in conjunction with a directory traversal (..) attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun SunOS | =5.8 | |
Oracle Solaris SPARC | =9.0 | |
Oracle Solaris SPARC | =9.0 | |
Oracle Solaris SPARC | =9.0-x86_update_2 | |
Oracle Solaris SPARC | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1354 is classified as a medium severity vulnerability due to its potential for information disclosure.
CVE-2004-1354 allows remote attackers to gather sensitive information by interpreting different 404 error messages generated by the Solaris Management Console.
CVE-2004-1354 affects Sun Solaris versions 8 and 9.
Mitigations for CVE-2004-1354 involve applying available patches and restricting access to the affected services.
The consequences of CVE-2004-1354 could include unauthorized disclosure of sensitive information through exploited error messages.