CVE-2009-1083: Code Injection
Sun Java System Identity Manager (IdM) 7.0 through 8.0 on Linux, AIX, Solaris, and HP-UX permits "control characters" in the passwords of user accounts, which allows remote attackers to execute arbitrary commands via vectors involving "resource adapters."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1083?
CVE-2009-1083 is considered a high-severity vulnerability due to the potential for remote command execution.
What software versions are affected by CVE-2009-1083?
CVE-2009-1083 affects Sun Java System Identity Manager versions 7.0 through 8.0.
How do I fix CVE-2009-1083?
To fix CVE-2009-1083, update Sun Java System Identity Manager to the latest patched version that does not permit control characters in passwords.
What type of attack does CVE-2009-1083 facilitate?
CVE-2009-1083 facilitates remote command execution attacks through the exploitation of control characters in passwords.
Is CVE-2009-1083 specific to any operating system?
CVE-2009-1083 is present across multiple operating systems including Linux, AIX, Solaris, and HP-UX.