CVE-2009-0348

Sun Java System Access Manager - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-0348. PoCs published by Marco Mella.

AI-analyzed exploit summary This Perl script exploits a username enumeration vulnerability in Sun Java System Access Manager and Identity Manager by analyzing HTTP responses to determine valid usernames. It checks for specific error messages in the response content or title to infer user existence.

Description

The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7.1 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Marco Mella · perlremotemultiple
https://www.exploit-db.com/exploits/32762

This Perl script exploits a username enumeration vulnerability in Sun Java System Access Manager and Identity Manager by analyzing HTTP responses to determine valid usernames. It checks for specific error messages in the response content or title to infer user existence.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Sun Java System Access Manager 6 2005Q1 (6.3), 7 2005Q4 (7.0), 7.1 and Sun Java System Identity Manager
No auth needed
Prerequisites: List of usernames to test · Network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/48283
Patch, Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-66-242026-1
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0269
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33489
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33688

Scores

EPSS 0.0816
EPSS Percentile 94.1%

Details

CWE
CWE-200
Status published
Products (3)
sun/java_system_access_manager 6.3_2005q1 (12 CPE variants)
sun/java_system_access_manager 7.1 (12 CPE variants)
sun/java_system_access_manager 7_2005q4 (12 CPE variants)
Published Jan 29, 2009
Tracked Since Feb 18, 2026