{ "id": "CVE-2008-2402", "sourceIdentifier": "cve@mitre.org", "published": "2008-06-04T20:32:00.000", "lastModified": "2017-08-08T01:31:01.013", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read password hashes and configuration data via direct requests for unspecified documents." }, { "lang": "es", "value": "EL Admin Server en Sun Java Active Server Pages (ASP) Server anterior a 4.0.3 almacena informaci\u00f3n sensible bajo el archivo web ra\u00edz sin el suficiente control de acceso, lo que permite a atacantes remotos leer hashes de contrase\u00f1as y datos de configuraci\u00f3n a trav\u00e9s de una petici\u00f3n directa a documentos sin especificar." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 5.0 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-264" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:sun:java_asp_server:*:*:*:*:*:*:*:*", "versionEndIncluding": "4.0.2", "matchCriteriaId": "27EAD95D-2E45-4DE1-95A2-3D1B71330774" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sun:java_asp_server:4.0:*:*:*:*:*:*:*", "matchCriteriaId": "9CC116F1-D43C-439E-BD12-2566D693032D" } ] } ] } ], "references": [ { "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=706", "source": "cve@mitre.org" }, { "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-66-238184-1", "source": "cve@mitre.org", "tags": [ "Patch" ] }, { "url": "http://www.securityfocus.com/bid/29540", "source": "cve@mitre.org" }, { "url": "http://www.securitytracker.com/id?1020187", "source": "cve@mitre.org" }, { "url": "http://www.vupen.com/english/advisories/2008/1742/references", "source": "cve@mitre.org" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42828", "source": "cve@mitre.org" } ] }