← All CVEs

CVE-2008-2402

medium · 5

The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read password hashes and configuration data via direct requests for unspecified documents.

5
CVSS
11.4%
EPSS (exploit prob.)
96th
EPSS percentile
2008-06-04
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
sunjava_asp_server<= 4.0.2
sunjava_asp_server4.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-2402