CVE-2008-0240 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 5.8% (pctl 93)
Patch early
A public exploit exists.
Description
/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 5.84% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-01-11 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| sun | java system identity manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Sun Java System Identity Manager 6.0/7.0/7.1 - '/idm/help/index.jsp?helpUrl' Remote Frame Injection | 2008-01-09 |
References
- http://secunia.com/advisories/28356
- http://securityreason.com/securityalert/3535
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-103180-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-200558-1
- http://www.procheckup.com/Vulnerability_PR07-10.php
- http://www.securityfocus.com/archive/1/486076/100/0/threaded
- http://www.securityfocus.com/bid/27214
- http://www.vupen.com/english/advisories/2008/0089
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39586
- http://secunia.com/advisories/28356
- http://securityreason.com/securityalert/3535
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-103180-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-200558-1
- http://www.procheckup.com/Vulnerability_PR07-10.php
- http://www.securityfocus.com/archive/1/486076/100/0/threaded
- http://www.securityfocus.com/bid/27214
- http://www.vupen.com/english/advisories/2008/0089
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39586
→ the Explorer · watch your stack · NVD