CVE-2008-5115: CSRF
Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hijack the authentication of administrators for requests that update the password via idm/admin/changeself.jsp.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5115?
CVE-2008-5115 is considered a high severity vulnerability due to its potential for cross-site request forgery against administrative functions.
How do I fix CVE-2008-5115?
To fix CVE-2008-5115, ensure that you apply the latest security patches released for Sun Java System Identity Manager.
Who is affected by CVE-2008-5115?
CVE-2008-5115 affects users of Sun Java System Identity Manager versions 6.0 up to SP4, 7.0, and 7.1.
What type of attack does CVE-2008-5115 permit?
CVE-2008-5115 permits remote attackers to hijack the authentication of administrators through cross-site request forgery.
What components are involved in CVE-2008-5115?
CVE-2008-5115 specifically involves the 'idm/admin/changeself.jsp' component of Sun Java System Identity Manager.