Java System Access Manager
Vendor:
First CVE: Feb 4, 2006 · Active for 20 years
16
Total CVEs
More Total CVEs than 92% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Java System Access Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 4, 2006
20 years ago
Most Recent CVE
Jan 19, 2011
5,665 days ago
CVE Severity & Scoring
Java System Access Manager16 CVEs
19%
50%
31%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown16 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown16 (100.0%)
User Interaction
None0 (0.0%)
Unknown16 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown16 (100.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-0348MEDIUM The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7.1 responds differently to a failed login attempt depending on whether the user acco | Jan 29, 2009 | 5.0 | 25 | NO | YES |
CVE-2008-2705HIGH Unspecified vulnerability in Sun Java System Access Manager (AM) 7.1, when used with certain versions and configurations of Sun Directory Server Enterprise Edition (DSEE), allows r | Jun 16, 2008 | 9.3 | 24 | NO | NO |
CVE-2009-0169HIGH Sun Java System Access Manager 7.1 allows remote authenticated sub-realm administrators to gain privileges, as demonstrated by creating the amadmin account in the sub-realm, and th | Jan 16, 2009 | 9.0 | 23 | NO | NO |
CVE-2007-5152HIGH Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container restart, which allows rem | Oct 1, 2007 | 7.5 | 22 | NO | NO |
CVE-2010-4444MEDIUM Unspecified vulnerability in Oracle Sun Java System Access Manager and Oracle OpenSSO 7, 7.1, and 8 allows remote attackers to affect confidentiality, integrity, and availability v | Jan 19, 2011 | 6.8 | 21 | NO | NO |
CVE-2007-5153MEDIUM Unspecified vulnerability in Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 8.x container, allows remote attackers to execute arbitrary | Oct 1, 2007 | 6.8 | 21 | NO | NO |
CVE-2010-0311MEDIUM Unspecified vulnerability in Sun Java System Identity Manager (aka IdM) 8.1.0.5 and 8.1.0.6, when Sun Java System Access Manager, OpenSSO Enterprise 8.0, or IBM Tivoli Access Manag | Jan 14, 2010 | 6.8 | 20 | NO | NO |
CVE-2008-2945HIGH Sun Java System Access Manager 6.3 through 7.1 and Sun Java System Identity Server 6.1 and 6.2 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which | Jun 30, 2008 | 7.5 | 20 | NO | NO |
CVE-2006-0531HIGH Unspecified vulnerability in Sun Java System Access Manager 7.0 allows local users logged in as "root" to bypass authentication and gain top-level administrator privileges via the | Feb 4, 2006 | 7.2 | 20 | NO | NO |
CVE-2009-0170MEDIUM Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1 allows remote authenticated users with console privileges to discover passwords, and obtain unspecified other "access t | Jan 16, 2009 | 6.0 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
6.2% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Java System Access Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7_2005q4 | 4 | 3.8 | 3.7% | 0 | 1 |
| 7.1 | 11 | 4.7 | 3.0% | 0 | 1 |
| 7.0_2005q4 | 5 | 3.5 | 1.6% | 0 | 0 |
| 7.0 | 5 | 5.8 | 1.3% | 0 | 0 |
| 6.3_2005q1 | 3 | 3.9 | 3.9% | 0 | 1 |
| 6.3 | 3 | 5.9 | 2.1% | 0 | 0 |
| 6.2 | 1 | 4.3 | 1.9% | 0 | 0 |
| 6.1 | 1 | 4.3 | 1.9% | 0 | 0 |
| 6.0_2005q1 | 1 | 2.6 | 1.7% | 0 | 0 |
| 6 | 1 | 2.6 | 1.7% | 0 | 0 |