First published: Fri Dec 12 2008(Updated: )
Open redirect vulnerability in console/faces/jsp/login/BeginLogin.jsp in Sun Java Web Console 3.0.2 through 3.0.5 and Solaris 10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the redirect_url parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java Web Console | =3.0.3 | |
Sun Java Web Console | =3.0.5 | |
Oracle Solaris and Zettabyte File System (ZFS) | =10 | |
Sun SunOS | =5.10 | |
Sun Java Web Console | =3.0.2 | |
Sun Java Web Console | =3.0.4 | |
Oracle Solaris and Zettabyte File System (ZFS) | =10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5550 is classified as a high severity vulnerability due to its potential for phishing attacks.
To fix CVE-2008-5550, upgrade to the latest version of Sun Java Web Console or apply the relevant patches provided by the vendor.
CVE-2008-5550 affects Sun Java Web Console versions 3.0.2 through 3.0.5 and Oracle Solaris 10.
CVE-2008-5550 is an open redirect vulnerability, allowing attackers to redirect users to malicious sites.
Yes, CVE-2008-5550 can be exploited by remote attackers without authentication.