Sun Java System Access Manager 7.1 allows remote authenticated sub-realm administrators to gain privileges, as demonstrated by creating the amadmin account in the sub-realm, and then logging in as amadmin in the root realm.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securitytracker.com/id?1021604 | vdb entry |
http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-02-1 | patch vendor advisory |
http://www.vupen.com/english/advisories/2009/0157 | vdb entry |
http://sunsolve.sun.com/search/document.do?assetkey=1-26-249106-1 | vendor advisory |
http://www.securityfocus.com/bid/33266 | patch vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/47944 | vdb entry |