Vulnerability Details CVE-2009-2712
Sun Java System Access Manager 6.3 2005Q1, 7.0 2005Q4, and 7.1; and OpenSSO Enterprise 8.0; when AMConfig.properties enables the debug flag, allows local users to discover cleartext passwords by reading debug files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 17.8%
CVSS Severity
CVSS v2 Score 2.1
Products affected by CVE-2009-2712
-
cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1
-
cpe:2.3:a:sun:java_system_access_manager:7.0_2005q4
-
cpe:2.3:a:sun:java_system_access_manager:7.1
-
cpe:2.3:a:sun:java_system_access_manager:7_2005q4
-
cpe:2.3:a:sun:java_system_web_server:7.0
-
cpe:2.3:a:sun:opensso_enterprise:8.0