First published: Wed Jul 01 2009(Updated: )
Cross-site scripting (XSS) vulnerability in the Cross-Domain Controller (CDC) servlet in Sun Java System Access Manager 6 2005Q1, 7 2005Q4, and 7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =6 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =6.0_2005q1 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =6.0_2005q1 | |
Sun Java System Access Manager | =6.0_2005q1 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =7.0_2005q4 | |
Sun Java System Access Manager | =6.0_2005q1 | |
Sun Java System Access Manager | =7.0_2005q4 | |
Sun Java System Access Manager | =7.0 | |
Sun Java System Access Manager | =6.0_2005q1 | |
Sun Java System Access Manager | =7.0_2005q4 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =7_2005q4 | |
Sun Java System Access Manager | =6.0_2005q1 | |
Sun Java System Access Manager | =7.0_2005q4 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =6.0_2005q1 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =7_2005q4 | |
Sun Java System Access Manager | =7.0_2005q4 | |
Sun Java System Access Manager | =7_2005q4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2268 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2009-2268, upgrade to a patched version of Sun Java System Access Manager beyond the vulnerable versions listed.
The impact of CVE-2009-2268 includes the ability for attackers to inject arbitrary web scripts or HTML, potentially leading to data theft or site defacement.
CVE-2009-2268 affects Sun Java System Access Manager versions 6.0_2005Q1, 7.0_2005Q4, and 7.1.
CVE-2009-2268 is a remote vulnerability, allowing attackers to exploit it without physical access to the affected system.