First published: Wed Jun 04 2008(Updated: )
The administration application server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to bypass authentication via direct requests on TCP port 5102.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java Asp Server | <=4.0.2 | |
Sun Java Asp Server | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2406 is classified as a medium severity vulnerability due to its authentication bypass potential.
To fix CVE-2008-2406, upgrade the Sun Java Active Server Pages Server to version 4.0.3 or later.
CVE-2008-2406 affects Sun Java Active Server Pages Server versions 4.0 and earlier, including both the 4.0 release and up to version 4.0.2.
Yes, CVE-2008-2406 can be exploited remotely by attackers who send direct requests to the server's TCP port 5102.
CVE-2008-2406 allows unauthorized users to bypass authentication controls, potentially leading to unauthorized access to the system.