Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2008-1286


Unspecified vulnerability in Sun Java Web Console 3.0.2, 3.0.3, and 3.0.4 allows remote attackers to bypass intended access restrictions and determine the existence of files or directories via unknown vectors.


Published

2008-03-11T17:44:00.000

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System sun solaris 8 No
Operating System sun solaris 8 No
Operating System sun solaris 9 No
Operating System sun solaris 9 No
Operating System sun solaris 10 No
Operating System sun solaris 10 No
Application sun java_web_console 3.0.2 Yes
Application sun java_web_console 3.0.3 Yes
Application sun java_web_console 3.0.4 Yes
Operating System linux linux_kernel * No
Application sun java_web_console 3.0.2 Yes

References