CVE-2009-1729: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3 allow remote attackers to inject arbitrary web script or HTML via (1) the abpersondisplayName parameter to uwc/abs/search.xml in the Add Contact implementation in the Personal Address Book component or (2) the temporaryCalendars parameter to uwc/base/UWCMain.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1729?
CVE-2009-1729 has been classified as a medium severity vulnerability due to its potential for exploitation via cross-site scripting.
How do I fix CVE-2009-1729?
To mitigate CVE-2009-1729, ensure that you are using the latest version of Sun Java System Communications Express and apply any available patches.
What systems are affected by CVE-2009-1729?
CVE-2009-1729 affects multiple versions of Sun Java System Communications Express, specifically versions 6.2 and 6.3 on various platforms.
What type of vulnerability is CVE-2009-1729?
CVE-2009-1729 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
Can CVE-2009-1729 be exploited remotely?
Yes, CVE-2009-1729 can be exploited remotely by attackers targeting the affected components of the software.