Security Intelligence Operations - Cisco Systems
Guest
 

Security Intelligence Operations


Sun Java System Application Server GlassFish Web Administrative Interface Multiple Cross-Site Scripting Vulnerabilities

 
Security Activity BulletinPowered by Cisco Security IntelliShield Alert Manager

Threat Type:IntelliShield: Security Activity Bulletin
IntelliShield ID:19013
Version:1
First Published:November 03, 2009 11:24 AM EST
Last Published:November 03, 2009 11:24 AM EST
Port:4848
CVE:CVE-2008-2751
BugTraq ID:29751
 
Urgency: Unlikely Use
Credibility: Highly Credible
Severity: Mild Damage
 
Version Summary:

Sun Java System Application Server contains multiple cross-site scripting vulnerabilities. Updates are not available.



Description

Sun Java System Application Server contains multiple cross-site scripting vulnerabilities.

The vulnerabilities exist in the GlassFish Web Administrative Interface component.  An unauthenticated, remote attacker could exploit one of these vulnerabilities by creating a malicious link and convincing a targeted user to follow it.   If the user clicks the link, the attacker could execute arbitrary script code in the user's browser in the security context of the affected site.

Proof-of-concept URLs are publicly available.

Sun has not confirmed this vulnerability and updated software is not available.

 
Alert History
 

Initial Release



Product Sets
 
The security vulnerability applies to the following combinations of products.

Primary Products:
N/A

Associated Products:
N/A



LEGAL DISCLAIMER
The urgency and severity ratings of this alert are not tailored to individual users; users may value alerts differently based upon their network configurations and circumstances. THE ALERT, AND INFORMATION CONTAINED THEREIN, ARE PROVIDED ON AN "AS IS" BASIS AND DO NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE ALERT, AND INFORMATION CONTAINED THEREIN, OR MATERIALS LINKED FROM THE ALERT, IS AT YOUR OWN RISK. INFORMATION IN THIS ALERT AND ANY RELATED COMMUNICATIONS IS BASED ON OUR KNOWLEDGE AT THE TIME OF PUBLICATION AND IS SUBJECT TO CHANGE WITHOUT NOTICE. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE ALERTS AT ANY TIME.