MEDIUM · 4.3

CVE-2004-2766

Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02 allows remote attackers to obtain unspecified "access" to e-mail via a crafted e-mail message, related to a "s...

Vulnerability Description

Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02 allows remote attackers to obtain unspecified "access" to e-mail via a crafted e-mail message, related to a "session hijacking" issue, a different vulnerability than CVE-2005-2022 and CVE-2006-5486.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
SunIplanet Messaging Server5.2
SunSolaris2.6
SunOne Messaging Server6.1
RedhatEnterprise Linux2.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2004-2766?

CVE-2004-2766 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02 allows remote attackers to obtain unspecified "access" to e-mail via a crafted e-mail message, related to a "s...

How severe is CVE-2004-2766?

CVE-2004-2766 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-2766?

Check the references section above for vendor advisories and patch information. Affected products include: Sun Iplanet Messaging Server, Sun Solaris, Sun One Messaging Server, Redhat Enterprise Linux.