First published: Wed May 30 2007(Updated: )
Cross-site scripting (XSS) vulnerability in Sun Java System Messaging Server 6.0 through 6.3, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly a related issue to CVE-2006-5653.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun iPlanet Messaging Server | =6.1 | |
Sun iPlanet Messaging Server | =6.0 | |
Sun iPlanet Messaging Server | =6.2 | |
Sun iPlanet Messaging Server | =6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-2904 is considered to be high due to the potential for attackers to exploit the XSS vulnerability.
To fix CVE-2007-2904, it is recommended to upgrade Sun Java System Messaging Server to a version that is not affected, ideally to version 6.4 or later.
CVE-2007-2904 affects users of Sun Java System Messaging Server versions 6.0 to 6.3 using Internet Explorer.
CVE-2007-2904 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages viewed by users.
While upgrading is the best option, a temporary workaround may include disabling or limiting the use of Internet Explorer for accessing the affected services.