|
|
>> Sun Java Messaging Server Cross Site Scripting Vulnerability
|
Title : Sun Java Messaging Server Cross Site Scripting Vulnerability VUPEN ID : VUPEN/ADV-2008-3152 CVE ID : CVE-2008-5098 CWE ID : CWE-79
Rated as : Low Risk 
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-11-14
|
A vulnerability has been identified in Sun Java Messaging Server, which could be exploited by attackers to execute arbitrary scripting code. This issue is caused by unspecified input validation errors when processing user-supplied data, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
Affected Products
Sun Java Messaging Server version 6.2
Sun Java Messaging Server version 6.3
Solution
Sun Java System Messaging Server 6.2 and 6.3 (for Solaris 9 and Solaris 10 / SPARC) - Apply patch 120228-29 or later
Sun Java System Messaging Server 6.3 (64-bit Solaris / SPARC) - Apply patch 126479-10 or later
Sun Java System Messaging Server 6.2 and 6.3 (for Solaris 9 and Solaris 10 / x86) - Apply patch 120229-29 or later
Sun Java System Messaging Server 6.3 (64-bit / x86) - Apply patch 126480-10 or later
Sun Java System Messaging Server 6.2 and 6.3 (for RHEL 3 and RHEL 4 / Linux) - Apply patch 120230-29 or later
References
http://www.vupen.com/english/advisories/2008/3152 http://sunsolve.sun.com/search/document.do?assetkey=1-66-242186-1
Credits
Vulnerability reported by Seth Hall (Ohio State University).
ChangeLog
2008-11-14 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|