Cross-site Scripting Vulnerability in Performance Reporting Module for Sun Management Center
CVE-2009-0857

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
9 March 2009

Summary

The Performance Reporting Module (PRM) in Sun Management Center versions 3.6.1 and 4.0 is susceptible to a cross-site scripting (XSS) vulnerability. This flaw allows remote attackers to inject arbitrary web scripts or HTML into the application through the msg parameter, which can potentially be exploited to gain unauthorized access to the SunMC Web Console. Proper input validation and output encoding are essential to mitigate this risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.