CVE-2008-0240: XSS
/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0240?
CVE-2008-0240 is considered a high severity vulnerability due to its potential for remote frame injection attacks.
How do I fix CVE-2008-0240?
To fix CVE-2008-0240, users should upgrade to the latest version of Sun Java System Identity Manager that is no longer vulnerable to frame injection.
What is the impact of exploiting CVE-2008-0240?
Exploiting CVE-2008-0240 allows attackers to inject malicious frames, potentially leading to phishing attacks and information theft.
Which versions of Sun Java System Identity Manager are affected by CVE-2008-0240?
CVE-2008-0240 affects versions 6.0 SP1 through SP3, as well as versions 7.0 and 7.1 of Sun Java System Identity Manager.
Is CVE-2008-0240 publicly known?
Yes, CVE-2008-0240 is a publicly known vulnerability that has been documented in various security advisories.