CVE-2009-2713: Medium severity oracle access manager vulnerability
The CDCServlet component in Sun Java System Access Manager 7.0 2005Q4 and 7.1, when Cross Domain Single Sign On (CDSSO) is enabled, does not ensure that "policy advice" is presented to the correct client, which allows remote attackers to obtain sensitive information via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2713?
CVE-2009-2713 is considered to have a medium severity rating due to its potential to expose sensitive information.
How do I fix CVE-2009-2713?
To fix CVE-2009-2713, you should update to a version of Sun Java System Access Manager that is not affected by the vulnerability.
What causes CVE-2009-2713 vulnerability?
CVE-2009-2713 is caused by the CDCServlet component failing to ensure proper presentation of policy advice to the correct client when CDSSO is enabled.
Which versions of Sun Java System Access Manager are affected by CVE-2009-2713?
CVE-2009-2713 affects Sun Java System Access Manager versions 6.3 2005Q1, 7.0 2005Q4, and 7.1.
What type of attack can exploit CVE-2009-2713?
CVE-2009-2713 can be exploited by remote attackers to obtain sensitive information through unspecified vectors.