CVE-2009-1796: XSS
Published May 26, 2009
·Updated
Cross-site scripting (XSS) vulnerability in Sun Java System Portal Server 6.3.1, 7.1, and 7.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to an error page.
Affected Software
12 affected components
Sun Java System Portal Server=6.3.1
Sun Java System Portal Server=7.1
Sun Java System Portal Server=7.2
Sun Java System Portal Server=7.1
Sun Java System Portal Server=6.3.1
Sun Java System Portal Server=6.3.1
Sun Java System Portal Server=7.1
Sun Java System Portal Server=7.1
Sun Java System Portal Server=7.2
Sun Java System Portal Server=6.3.1
Sun Java System Portal Server=7.2
Sun Java System Portal Server=7.2
Remediation
Patch Available
Event History
May 26, 2009
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1796?
CVE-2009-1796 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2009-1796?
To fix CVE-2009-1796, update your Sun Java System Portal Server to a version that has addressed this vulnerability.
3
What software is affected by CVE-2009-1796?
CVE-2009-1796 affects Sun Java System Portal Server versions 6.3.1, 7.1, and 7.2.
4
What type of vulnerability is CVE-2009-1796?
CVE-2009-1796 is a cross-site scripting (XSS) vulnerability allowing remote attackers to inject scripts into web pages.
5
Can CVE-2009-1796 affect user data?
Yes, CVE-2009-1796 can potentially lead to unauthorized access to user data through malicious script injection.