Article ID : 253267
Article Type : Sun Alert
Last reviewed : 2010-01-20
Audience : PUBLIC
Keywords :
Copyright Notice: Copyright © 2009 Sun Microsystems, Inc. All Rights Reserved

Sun Java System Identity Manager Security Vulnerabilities



Category :Security
Release Phase :Resolved
Bug Id :17763, 18052, 18104, 18578, 18946, 19033, 19115, 19595, 19659, 19660, 19661, 19683, 20174, 20224, 20352  
Date of Resolved Release :19-Mar-2009 
Product :Sun Java System Identity Manager 7.0
Sun Java System Identity Manager 7.1
Sun Java System Identity Manager 8.0  

Sun Java System Identity Manager Security Vulnerabilities (see below for full details)


1. Impact

Sun Java System Identity Manager (IdM) is affected by multiple security
vulnerabilities with varying impacts as follows:

A remote unprivileged user may be able to gain unauthorized access to data being
transferred between clients and the IdM server due to some connections not being
secured with SSL (17763).

A local or remote unprivileged user may be able to determine the existence of
valid IdM account names (18052, 18104).

A user with an account on the IdM server may be able to change the password
of other IdM accounts (18578).

A user with an account on the IdM server may be able to perform some
actions with additional capabilities than those assigned (18946, 20352).

A remote unprivileged user may be able to execute unauthorized HTML code or
client-side scripts in a user's browser due to multiple Cross-Site Scripting
(XSS) vulnerabilities (19033, 19595, 19659, 19660, 19661, 19683).

A user with an account on the IdM server may be able to submit arbitrary
commands to the Admin Console and then be able to perform administrative
actions such as creating accounts (19115).

A local or remote unprivileged user may be able to execute arbitrary
commands on Unix/Linux based resource adapters (20174).

A local or remote unprivileged user may be able to modify IdM system
configuration data (20224).

Sun acknowledges with thanks Dan Sinclair of Security Compass for bringing
issue 19033 to our attention.

Sun acknowledges with thanks ProCheckUp Ltd for bringing issues 19595 and
19661 to our attention.

Sun acknowledges with thanks Alexandre Bezroutchko of Scanit for bringing
issue 20174 to our attention.

Sun acknowledges with thanks, Marco Mella (http://www.aboutsecurity.net/) for
bringing issue 18052 to our attention.

2. Contributing Factors

These issues can occur in the following releases:
Notes:
Identity Manager 8.1 is not affected by these issues.

To determine the version of Sun Java System Identity Manager installed on a system, log in to the administrator console using a browser and hover the mouse pointer over the "Help" tab in the upper right portion of the masthead. The current version will be displayed similar to the following:

      
Version Sun Java System Identity Manager 7.0 (20070523)

3. Symptoms

There are no predictable symptoms that would indicate the described issues have been exploited.


4. Workaround

There are no workarounds for these issues.  Please see the Resolution section below.



5. Resolution

These issues are addressed in the following releases: Note: for all Identity Manager supported platforms refer to your installation guide. See patch README for other patch dependencies.


For more information on Security Sun Alerts, see Technical Instruction ID 213557
http://sunsolve.sun.com/search/document.do?assetkey=1-61-213557-1


This Sun Alert notification is being provided to you on an "AS IS" basis. This Sun Alert notification may contain information provided by third parties. The issues described in this Sun Alert notification may or may not impact your system(s). Sun makes no representations, warranties, or guarantees as to the information contained herein. ANY AND ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT, ARE HEREBY DISCLAIMED. BY ACCESSING THIS DOCUMENT YOU ACKNOWLEDGE THAT SUN SHALL IN NO EVENT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES THAT ARISE OUT OF YOUR USE OR FAILURE TO USE THE INFORMATION CONTAINED HEREIN. This Sun Alert notification contains Sun proprietary and confidential information. It is being provided to you pursuant to the provisions of your agreement to purchase services from Sun, or, if you do not have such an agreement, the Sun.com Terms of Use. This Sun Alert notification may only be used for the purposes contemplated by these agreements.

Copyright 2000-2009 Sun Microsystems, Inc., 4150 Network Circle, Santa Clara, CA 95054 U.S.A. All rights reserved.



Modification History

20-Mar-2009 Modification to Impact section




Attachments
This solution has no attachment