CVE-2008-1286 |
|
发布时间 :2008-03-11 13:44:00 | ||
修订时间 :2011-03-07 22:06:27 | ||||
NMC |
[原文]Unspecified vulnerability in Sun Java Web Console 3.0.2, 3.0.3, and 3.0.4 allows remote attackers to bypass intended access restrictions and determine the existence of files or directories via unknown vectors.
[CNNVD]sun java_web_console 访问权限绕过漏洞(CNNVD-200803-184)
Sun Java Web Console存在未知漏洞。远程攻击者绕过预设的访问限制和通过未知向量来决定文件或目录的存在。
–
CVSS (基础分值)
CVSS分值: | 7.8 | [严重(HIGH)] |
机密性影响: | COMPLETE | [完全的信息泄露导致所有系统文件暴露] |
完整性影响: | NONE | [不会对系统完整性产生影响] |
可用性影响: | NONE | [对系统可用性无影响] |
攻击复杂度: | LOW | [漏洞利用没有访问限制 ] |
攻击向量: | NETWORK | [攻击者不需要获取内网访问权或本地访问权] |
身份认证: | NONE | [漏洞利用无需身份认证] |
–
CPE (受影响的平台与产品)
cpe:/a:sun:java_web_console:3.0.2 | |
cpe:/a:sun:java_web_console:3.0.3 | |
cpe:/a:sun:java_web_console:3.0.4 |
–
OVAL (用于检测的技术细节)
未找到相关OVAL定义 |
–
官方数据库链接
–
其它链接及资源
http://www.securityfocus.com/bid/28155 (PATCH) BID 28155 |
http://sunsolve.sun.com/search/document.do?assetkey=1-26-231526-1 (PATCH) SUNALERT 231526 |
http://xforce.iss.net/xforce/xfdb/41069 (UNKNOWN) XF sun-javawebconsole-information-disclosure(41069) |
http://www.vupen.com/english/advisories/2008/0806/references (UNKNOWN) VUPEN ADV-2008-0806 |
http://www.securitytracker.com/id?1019574 (UNKNOWN) SECTRACK 1019574 |
http://secunia.com/advisories/29290 (VENDOR_ADVISORY) SECUNIA 29290 |
–
漏洞信息
sun java_web_console 访问权限绕过漏洞 | |
高危 | 资料不足 |
2008-03-11 00:00:00 | 2008-09-05 00:00:00 |
远程 | |
Sun Java Web Console存在未知漏洞。远程攻击者绕过预设的访问限制和通过未知向量来决定文件或目录的存在。 |
–
公告与补丁
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接: Sun Solaris 9_x86 Sun 125951-07 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -125951-07-1 Sun Solaris 8_x86 Sun 136986-01 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -136986-01-1 Sun Solaris 10 Sun 125952-07 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -125952-07-1 Sun Solaris 8 Sun 136987-01 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -136987-01-1 Sun Solaris 9 Sun 125950-07 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -125950-07-1 Sun Solaris 10_x86 Sun 125953-07 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -125953-07-1 Sun Java Web Console 3.0.2 Sun 125954-07 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -125954-07-1 |