First published: Wed Mar 25 2009(Updated: )
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying workflows, which allows remote authenticated users to have an unspecified impact.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java System Identity Manager | =7.1.1 | |
Sun Java System Identity Manager | =7.0 | |
Sun Java System Identity Manager | =7.1 | |
Sun Java System Identity Manager | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1078 has been identified as a moderate severity vulnerability due to its impact on privilege requirements.
To fix CVE-2009-1078, you should upgrade your Sun Java System Identity Manager to a patched version that addresses these privilege issues.
CVE-2009-1078 affects Sun Java System Identity Manager versions 7.0 through 8.0.
CVE-2009-1078 allows remote authenticated users to delete audit policies and modify workflows without appropriate permissions, potentially compromising system integrity.
Yes, CVE-2009-1078 can be exploited by remote authenticated users, allowing them to perform unauthorized actions.