cvelist/2008/2xxx/CVE-2008-2402.json

93 lines
2.7 KiB
JSON

{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org",
"ID" : "CVE-2008-2402",
"STATE" : "PUBLIC"
},
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "n/a",
"version" : {
"version_data" : [
{
"version_value" : "n/a"
}
]
}
}
]
},
"vendor_name" : "n/a"
}
]
}
},
"data_format" : "MITRE",
"data_type" : "CVE",
"data_version" : "4.0",
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read password hashes and configuration data via direct requests for unspecified documents."
}
]
},
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng",
"value" : "n/a"
}
]
}
]
},
"references" : {
"reference_data" : [
{
"name" : "20080603 Sun Java System Active Server Pages Information Disclosure Vulnerability",
"refsource" : "IDEFENSE",
"url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=706"
},
{
"name" : "238184",
"refsource" : "SUNALERT",
"url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-66-238184-1"
},
{
"name" : "29540",
"refsource" : "BID",
"url" : "http://www.securityfocus.com/bid/29540"
},
{
"name" : "ADV-2008-1742",
"refsource" : "VUPEN",
"url" : "http://www.vupen.com/english/advisories/2008/1742/references"
},
{
"name" : "1020187",
"refsource" : "SECTRACK",
"url" : "http://www.securitytracker.com/id?1020187"
},
{
"name" : "30523",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/30523"
},
{
"name" : "sunjava-active-password-info-disclosure(42828)",
"refsource" : "XF",
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42828"
}
]
}
}