Vulnerability Description
The Java Management Extensions Remote API Remote Method Invocation over Internet Inter-ORB Protocol (JMX RMI-IIOP) API in Java Dynamic Management Kit 5.1 before 20070309 does not properly enforce the java.policy, which allows local users to obtain certain MBeans data access by operating a server application accessed by a privileged remote authenticated user.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun | Java Dynamic Management Kit | 5.1 |
References
- http://osvdb.org/34018
- http://secunia.com/advisories/24497
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102835-1Patch
- http://www.securityfocus.com/bid/22907
- http://www.securitytracker.com/id?1017745
- http://www.vupen.com/english/advisories/2007/0906
- http://osvdb.org/34018
- http://secunia.com/advisories/24497
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102835-1Patch
- http://www.securityfocus.com/bid/22907
- http://www.securitytracker.com/id?1017745
- http://www.vupen.com/english/advisories/2007/0906
FAQ
What is CVE-2007-1419?
CVE-2007-1419 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Java Management Extensions Remote API Remote Method Invocation over Internet Inter-ORB Protocol (JMX RMI-IIOP) API in Java Dynamic Management Kit 5.1 before 20070309 does not properly enforce the ...
How severe is CVE-2007-1419?
CVE-2007-1419 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-1419?
Check the references section above for vendor advisories and patch information. Affected products include: Sun Java Dynamic Management Kit.