Latest Comments
"nothing"
by UMAIR | Jul 4, 2009 5:54 PM
 
"Thank you "
by Dr. Holub | Jul 4, 2009 11:17 AM
 
"Agree that wireless hotspots are an easy way for hackers to gather information from connected ..."
by Patrick Hooper | Jul 3, 2009 4:06 AM
 
"Katarzyna what has this got to do with Symantec?? "
by PaulC | Jul 2, 2009 12:55 PM
 
"Hi Nadim, I'm the chief marketing officer at Ounce Labs, and I disagree with your statement. ..."
by Jennifer Sullivan | Jun 30, 2009 11:56 PM

Vulnerability detected in Sun Microsystem's communications and collaboration application

  • Email a Friend
  • Print Page
By SC Staff
May 26, 2009 9:58 AM
Tags: Vulnerability | Sun | Microsystem's | collaboration | Oracle
A vulnerability has been detected in Sun Microsystem's java system communications express web-based collaboration application.

A vulnerability has been detected in Sun's java system communications express web-based communications and collaboration application.

 Detected by Core Security Technologies, the vulnerability exists in a remote access element of Sun's Java Communications Suite, which if leveraged, could allow attackers to target users of the application through exploitation of cross-site scripting (XSS) bugs.

 

The first XSS vulnerability, which is resident in the personal address book's 'add contact' functionality, concerns the affected URL that is originally accessed thru a post request, and the flaw can be exploited both with a get and with a post request.

 

A second vulnerability concerns the contents of the URL, which are not encoded at the time of using them in HTML output, therefore allowing an attacker who controls their content to insert JavaScript code. This vulnerability can be exploited through a get request, and the user does not need to be logged into the web application.

 

CoreLabs immediately alerted the Sun security coordination team to the vulnerabilities, and the two companies have since synchronised efforts to ensure that patches could be created and made available to protect users of the program. 

 

Ivan Arce, CTO of Core Security Technologies, said: “XSS bugs are popular among attackers attempting to coax web applications into providing control of end users' web browsers to carry out a wide range of malicious schemes. It is very important that organisations take the necessary steps to ensure that the applications they build or licence from third parties are not susceptible to these types of exploits.”

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Exclusive Data Centre - Sponsored Content by Microsoft
 
Vulnerabilities & Exploits Whitepapers