{ "id": "CVE-2008-5117", "sourceIdentifier": "cve@mitre.org", "published": "2008-11-18T00:30:00.437", "lastModified": "2024-11-21T00:53:19.530", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Open redirect vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors." }, { "lang": "es", "value": "Vulnerabilidad involuntaria de redirecci\u00f3n en Sun Java System Identity Manager v6.0 a v6.0 SP4, v7.0, y v7.1, permite a atacantes remotos, redireccionar a usuarios a sitios web de su elecci\u00f3n y llevar a cabo ataques de phishing a trav\u00e9s de vectores no especificados." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:P", "baseScore": 6.4, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL" }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 4.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-20" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:sun:java_system_identity_manager:6.0:*:*:*:*:*:*:*", "matchCriteriaId": "13445915-DF3D-4C52-B1DC-9FC6BE0DD519" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sun:java_system_identity_manager:6.0:sp1:*:*:*:*:*:*", "matchCriteriaId": "D0C2964C-7435-4999-AF16-01CD9EF5782C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sun:java_system_identity_manager:6.0:sp2:*:*:*:*:*:*", "matchCriteriaId": "51CFF484-5A52-41DC-A003-A9319DF2AFB8" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sun:java_system_identity_manager:6.0:sp3:*:*:*:*:*:*", "matchCriteriaId": "9A7E88DA-F3A8-4B0F-AD4F-8680C1FB3282" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sun:java_system_identity_manager:6.0:sp4:*:*:*:*:*:*", "matchCriteriaId": "861DEDA3-93A1-405A-BA2F-764AE4219D89" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sun:java_system_identity_manager:7.0:*:*:*:*:*:*:*", "matchCriteriaId": "0980492E-B7DB-4B9F-A400-FDC47DB89A95" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sun:java_system_identity_manager:7.1:*:*:*:*:*:*:*", "matchCriteriaId": "3A5C87C0-3734-4568-97A6-6AB8979AABE7" } ] } ] } ], "references": [ { "url": "http://osvdb.org/49768", "source": "cve@mitre.org" }, { "url": "http://secunia.com/advisories/32606", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-243386-1", "source": "cve@mitre.org", "tags": [ "Patch", "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/bid/32262", "source": "cve@mitre.org" }, { "url": "http://www.securitytracker.com/id?1021170", "source": "cve@mitre.org" }, { "url": "http://www.vupen.com/english/advisories/2008/3128", "source": "cve@mitre.org" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46556", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/49768", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://secunia.com/advisories/32606", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-243386-1", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch", "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/bid/32262", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.securitytracker.com/id?1021170", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.vupen.com/english/advisories/2008/3128", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46556", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }