CVE-2009-0170: Medium severity Sun Java System Access Manager vulnerability
Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1 allows remote authenticated users with console privileges to discover passwords, and obtain unspecified other "access to resources," by visiting the Configuration Items component in the console.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to the administrative console and specifically the "Configuration Items" component of Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1 using firewall rules/ACLs or a management network so only trusted administrator IPs/hosts can reach the console.
- Operational
Audit all accounts with console privileges in Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1; remove/revoke console privileges from any user who does not require them, and rotate credentials for accounts that may have had passwords exposed.
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0170?
CVE-2009-0170 is considered a high severity vulnerability due to its potential to allow unauthorized discovery of passwords and access to sensitive resources.
How do I fix CVE-2009-0170?
To fix CVE-2009-0170, upgrade to a version of Sun Java System Access Manager that is not affected by this vulnerability.
Who is affected by CVE-2009-0170?
CVE-2009-0170 affects users of Sun Java System Access Manager versions 6.3, 7.0_2005Q4, and 7.1 with console privileges.
What impact does CVE-2009-0170 have?
CVE-2009-0170 potentially allows authenticated users to discover passwords and gain access to restricted resources.
Is CVE-2009-0170 being actively exploited?
There is no public information confirming that CVE-2009-0170 is being actively exploited, but it poses a significant security risk.