|
| |
|
Security Intelligence Operations
Sun Java System Application Server GlassFish Web Administrative Interface Multiple Cross-Site Scripting Vulnerabilities |
| |
| Security Activity Bulletin | Powered by  |
|
|
| Threat Type: | IntelliShield: Security Activity Bulletin |
|
| IntelliShield ID: | 19013 |
| Version: | 1 |
| First Published: | November 03, 2009 11:24 AM EST |
| Last Published: | November 03, 2009 11:24 AM EST |
| Port: | 4848 |
| CVE: | CVE-2008-2751 |
| BugTraq ID: | 29751 |
| |
| Urgency: |
Unlikely Use
|  |
| Credibility: |
Highly Credible
|  |
| Severity: |
Mild Damage
|  |
|
|
| |
| Version Summary: | Sun Java System Application Server contains multiple cross-site scripting vulnerabilities. Updates are not available. |
|
Description |
|
Sun Java System Application Server contains multiple cross-site scripting vulnerabilities.
The vulnerabilities exist in the GlassFish Web Administrative Interface component. An unauthenticated, remote attacker could exploit one of these vulnerabilities by creating a malicious link and convincing a targeted user to follow it. If the user clicks the link, the attacker could execute arbitrary script code in the user's browser in the security context of the affected site.
Proof-of-concept URLs are publicly available.
Sun has not confirmed this vulnerability and updated software is not available. |
| |
| Alert History |
| |
Initial Release |
|
Product Sets |
| |
The security vulnerability applies to the following combinations of products.
|
|
LEGAL DISCLAIMER
The urgency and severity ratings of this alert are not tailored to individual users; users may value alerts differently based upon their network configurations and circumstances. THE ALERT, AND INFORMATION CONTAINED THEREIN, ARE PROVIDED ON AN "AS IS" BASIS AND DO NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE ALERT, AND INFORMATION CONTAINED THEREIN, OR MATERIALS LINKED FROM THE ALERT, IS AT YOUR OWN RISK. INFORMATION IN THIS ALERT AND ANY RELATED COMMUNICATIONS IS BASED ON OUR KNOWLEDGE AT THE TIME OF PUBLICATION AND IS SUBJECT TO CHANGE WITHOUT NOTICE. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE ALERTS AT ANY TIME. |
|
|
| |