Insecure File Permissions in Sun ONE Application Server 7.0 for Windows
CVE-2003-0414

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
30 June 2003

Summary

The Sun ONE Application Server 7.0 for Windows creates a statefile with world-readable permissions, which inadvertently exposes sensitive information. This vulnerability allows local users to access and read a plaintext password stored in the statefile, leading to potential unauthorized access to the server and its services. Organizations using this application should review their file permission configurations to mitigate the risk of privilege escalation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.