Overview
There is a vulnerability in the Sun Java System Portal Server, which could allow a remote, authenticated user to gain access to the administrative credentials of the Calendar server.
Description
The Sun Java System Portal Server is a content management system that provides centralized login capabilities and administration. The Calendar Server is an optional product that can be used by the portal server to provide users the ability to collaboratively manage schedules and share resources. A vulnerability exists in the way changes to the display options are handled by the Sun Java System Portal Server. By changing the display options to a non-default view, a user could gain access to the administrative credentials on the Calendar Server. According to the Sun Security Alert, this vulnerability only occurs if the following two conditions are true:
|
Impact
A remote, authenticated user could gain access to the administrative credentials of the Calendar server. |
Solution
Apply Patch |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57586
- http://wwws.sun.com/software/products/portal_srvr/home_portal.html
- http://wwws.sun.com/software/products/calendar_srvr/home_calendar.html
- http://docs.sun.com/source/816-6748-10/comm_config.html#wp34042
- http://secunia.com/advisories/12134/
- http://www.securitytracker.com/alerts/2004/Jul/1010756.html
Acknowledgements
This vulnerability was reported by Sun Microsystems.
This document was written by Damon Morda.
Other Information
CVE IDs: | None |
Severity Metric: | 1.31 |
Date Public: | 2004-07-21 |
Date First Published: | 2004-07-23 |
Date Last Updated: | 2004-07-23 15:13 UTC |
Document Revision: | 17 |