First published: Fri Jan 11 2008(Updated: )
/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java System Identity Manager | =6.0-sp2 | |
Sun Java System Identity Manager | =7.0 | |
Sun Java System Identity Manager | =6.0-sp1 | |
Sun Java System Identity Manager | =7.1 | |
Sun Java System Identity Manager | =6.0-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0240 is considered a high severity vulnerability due to its potential for remote frame injection attacks.
To fix CVE-2008-0240, users should upgrade to the latest version of Sun Java System Identity Manager that is no longer vulnerable to frame injection.
Exploiting CVE-2008-0240 allows attackers to inject malicious frames, potentially leading to phishing attacks and information theft.
CVE-2008-0240 affects versions 6.0 SP1 through SP3, as well as versions 7.0 and 7.1 of Sun Java System Identity Manager.
Yes, CVE-2008-0240 is a publicly known vulnerability that has been documented in various security advisories.