CVE-2007-1419

high

Description

The Java Management Extensions Remote API Remote Method Invocation over Internet Inter-ORB Protocol (JMX RMI-IIOP) API in Java Dynamic Management Kit 5.1 before 20070309 does not properly enforce the java.policy, which allows local users to obtain certain MBeans data access by operating a server application accessed by a privileged remote authenticated user.

References

http://www.vupen.com/english/advisories/2007/0906

http://www.securitytracker.com/id?1017745

http://www.securityfocus.com/bid/22907

http://sunsolve.sun.com/search/document.do?assetkey=1-26-102835-1

http://secunia.com/advisories/24497

http://osvdb.org/34018

Details

Source: Mitre, NVD

Published: 2007-03-12

Updated: 2011-03-08

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High