First published: Mon Oct 01 2007(Updated: )
Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container restart, which allows remote attackers to perform administrative tasks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Access Manager | =7.1 | |
Oracle Access Manager | =7.1 | |
Oracle Access Manager | =7.1 | |
Oracle Access Manager | =7.1 | |
Sun ONE Application Server | =9.1 | |
Oracle Access Manager | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5152 is considered to have a medium severity due to the potential for unauthorized administrative access.
To fix CVE-2007-5152, ensure that authentication is properly enforced after a container restart by applying any relevant patches or updates to Sun Java System Access Manager.
CVE-2007-5152 affects Sun Java System Access Manager 7.1 and Sun Java System Application Server 9.1.
Yes, CVE-2007-5152 can be exploited remotely without authentication after a server restart.
CVE-2007-5152 can allow attackers to perform administrative tasks, potentially compromising the entire system.