CVE-2004-1354: Path Traversal
The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inaccessible, which could allow remote attackers to obtain sensitive information in conjunction with a directory traversal (..) attack.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1354?
CVE-2004-1354 is classified as a medium severity vulnerability due to its potential for information disclosure.
How does CVE-2004-1354 exploit the system?
CVE-2004-1354 allows remote attackers to gather sensitive information by interpreting different 404 error messages generated by the Solaris Management Console.
Which Solaris versions are affected by CVE-2004-1354?
CVE-2004-1354 affects Sun Solaris versions 8 and 9.
How can I mitigate the risks associated with CVE-2004-1354?
Mitigations for CVE-2004-1354 involve applying available patches and restricting access to the affected services.
What are the potential consequences of CVE-2004-1354?
The consequences of CVE-2004-1354 could include unauthorized disclosure of sensitive information through exploited error messages.