← Vulnerability feed

Vulnerability record · CVE-2008-5117 · published 18 November 2008

CVE-2008-5117: Sun java system identity manager improper input validation vulnerability

Sun · Java System Identity Manager

Open redirect vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

6.4 CVSS 2.0 Medium EPSS 2.6% · top 15.2% CWE-20 · Improper input validation
6.4CVSS 2.0 base score
2.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

Open redirect vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

AV:N/AC:L/Au:N/C:N/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-5117 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2009-1082Sun java system identity manager improper input validation vulnerabilitySun Java System Identity Manager (IdM) 7.0 through 8.0 allows remote authenticated users to gain privileges by submitting crafted commands to the Adm…EPSS 3.4%9.0CVE-2009-1083Sun java system identity manager code injection vulnerabilitySun Java System Identity Manager (IdM) 7.0 through 8.0 on Linux, AIX, Solaris, and HP-UX permits "control characters" in the passwords of user accoun…EPSS 3.7%7.8CVE-2008-5116Sun java system identity manager path traversal vulnerabilityDirectory traversal vulnerability in idm/includes/helpServer.jsp in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote …EPSS 4.1%6.8CVE-2008-5115Sun java system identity manager cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hija…EPSS 3.1%6.5CVE-2009-1077Sun java system identity manager permissions and access controls vulnerabilityThe Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresC…EPSS 2.5%6.4CVE-2009-1084Sun java system identity manager permissions and access controls vulnerabilitySun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote auth…EPSS 2.6%5.8CVE-2008-0241Sun java system identity manager improper input validation vulnerabilityOpen redirect vulnerability in /idm/user/login.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to r…EPSS 2.7%5.0CVE-2009-1074Sun java system identity manager vulnerabilitySun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to …EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2008-5117), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.