CVE-2005-2022 describes an unknown vulnerability, likely a cross-site scripting (XSS) flaw, in the Webmail component of iPlanet Messaging Server 5.2 Patch 1 and Sun ONE Messaging Server 6.2. This vulnerability allows remote attackers to execute arbitrary JavaScript. With a CVSS score of 4.3, it is of medium attack complexity and requires no authentication, potentially leading to information disclosure (partial impact) but not affecting confidentiality or availability. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While it has received minimal community discussion, it is not on the CISA KEV catalog and is considered inactive.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2CPE matchmatch criteria | cpe:2.3:a:sun:iplanet_messaging_server:5.2:*:*:*:*:*:*:* | ||
6.2CPE matchmatch criteria | cpe:2.3:a:sun:one_messaging_server:6.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.