First published: Tue Nov 18 2008(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java System Identity Manager | =6.0-sp2 | |
Sun Java System Identity Manager | =7.0 | |
Sun Java System Identity Manager | =6.0-sp1 | |
Sun Java System Identity Manager | =7.1 | |
Sun Java System Identity Manager | =6.0-sp3 | |
Sun Java System Identity Manager | =6.0-sp4 | |
Sun Java System Identity Manager | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5114 is classified as a medium severity vulnerability due to its potential for remote exploitation through XSS attacks.
To fix CVE-2008-5114, update to the latest version of Sun Java System Identity Manager that addresses the XSS vulnerabilities.
CVE-2008-5114 affects Sun Java System Identity Manager versions 6.0 through 6.0 SP4 and 7.0, 7.1.
CVE-2008-5114 contains multiple cross-site scripting (XSS) vulnerabilities that allow for the injection of arbitrary web scripts.
Yes, CVE-2008-5114 can be exploited remotely, allowing attackers to execute scripts in the context of the victim's session.