Multiple vulnerabilities have been identified in Sun Java System Identity Manager, which could be exploited by remote attackers to bypass security restrictions or gain knowledge of sensitive information. These issues are caused by unspecified input validation errors which could be exploited to conduct cross-site scripting attacks, gain unauthorized access to the Administrator account or to certain files on the IDM server's filesystem, or redirect the browser to unintended remote sites, or to inject frames containing data from unintended sites.
Sun Java System Identity Manager 6.0 - Apply patches 136848-02 or later and 139081-01 or later
Sun Java System Identity Manager 6.0 SP1 - Apply patches 136849-02 or later and 139082-01 or later
Sun Java System Identity Manager 6.0 SP2 - Apply patches 136850-02 or later and 139083-01 or later
Sun Java System Identity Manager 6.0 SP3 - Apply patches 136851-02 or later and 139084-01 or later
Sun Java System Identity Manager 6.0 SP4 - Apply patch 139085-01 or later
Sun Java System Identity Manager 7.0 - Apply patches 136852-02 or later and 139086-01 or later
Sun Java System Identity Manager 7.1 - Apply patches 136853-02 or later and 139087-01 or later References