Cross-Site Request Forgery Vulnerability in Sun Java System Identity Manager
CVE-2008-5115

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 November 2008

Summary

The vulnerability allows remote attackers to exploit the Sun Java System Identity Manager by forging user requests. This security flaw enables unauthorized individuals to hijack administrator authentication, particularly during password updates through specific endpoints, potentially compromising sensitive account information. Proper security measures and updates are essential to mitigate such risks and safeguard against unauthorized access.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.