First published: Thu Dec 03 2009(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the Gateway component in Sun Java System Portal Server 6.3.1, 7.1, and 7.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java System Portal Server | =7.1 | |
Sun Java System Portal Server | =6.3.1 | |
Sun Java System Portal Server | =7.2 | |
Sun Java System Portal Server | =7.1 | |
Sun Java System Portal Server | =7.2 | |
Oracle Solaris SPARC | =9 | |
Oracle Solaris SPARC | =9 | |
Oracle Solaris SPARC | =10 | |
Oracle Solaris SPARC | =10 | |
Sun Java System Portal Server | =6.3.1 | |
Oracle Solaris SPARC | =8 | |
Oracle Solaris SPARC | =8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-4187 is classified as medium due to its potential for cross-site scripting attacks.
To fix CVE-2009-4187, it is recommended to update the Sun Java System Portal Server to a patched version that addresses these vulnerabilities.
CVE-2009-4187 affects Sun Java System Portal Server versions 6.3.1, 7.1, and 7.2.
CVE-2009-4187 can facilitate cross-site scripting (XSS) attacks by allowing remote attackers to inject arbitrary web scripts or HTML.
Currently, the best approach for CVE-2009-4187 is to apply the available patches rather than relying on workarounds.