PoC Index

CVE-2008-5115

MEDIUM 6.8EPSS 3.2%

Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hijack the authentication of administrators for requests that update the password via idm/admin/changeself.jsp.

CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
3.16% chance of exploitation in the next 30 days, 87th percentile
Published
2008-11-18
Updated
2024-08-07

ExploitDB entries (1)

References

Related