Описание
/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."
Ссылки
- Vendor Advisory
- ExploitPatch
- Vendor Advisory
- ExploitPatch
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:sun:java_system_identity_manager:6.0:sp1:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_identity_manager:6.0:sp2:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_identity_manager:6.0:sp3:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_identity_manager:7.0:*:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_identity_manager:7.1:*:*:*:*:*:*:*
EPSS
Процентиль: 92%
0.07365
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
почти 4 года назад
/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."
EPSS
Процентиль: 92%
0.07365
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79