← Vulnerability feed

Vulnerability record · CVE-2009-1083 · published 25 March 2009

CVE-2009-1083: Sun java system identity manager code injection vulnerability

Sun · Java System Identity Manager

Sun Java System Identity Manager (IdM) 7.0 through 8.0 on Linux, AIX, Solaris, and HP-UX permits "control characters" in the passwords of user accounts, which allows remote attackers to execute arbitrary commands via vectors involving "resource adapters."

9.0 CVSS 2.0 High EPSS 3.7% · top 10.7% CWE-94 · Code injection
9.0CVSS 2.0 base score
3.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

Sun Java System Identity Manager (IdM) 7.0 through 8.0 on Linux, AIX, Solaris, and HP-UX permits "control characters" in the passwords of user accounts, which allows remote attackers to execute arbitrary commands via vectors involving "resource adapters."

AV:N/AC:L/Au:S/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-1083 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2009-1082Sun java system identity manager improper input validation vulnerabilitySun Java System Identity Manager (IdM) 7.0 through 8.0 allows remote authenticated users to gain privileges by submitting crafted commands to the Adm…EPSS 3.4%7.8CVE-2008-5116Sun java system identity manager path traversal vulnerabilityDirectory traversal vulnerability in idm/includes/helpServer.jsp in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote …EPSS 4.1%6.8CVE-2008-5115Sun java system identity manager cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hija…EPSS 3.1%6.5CVE-2009-1077Sun java system identity manager permissions and access controls vulnerabilityThe Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresC…EPSS 2.5%6.4CVE-2009-1084Sun java system identity manager permissions and access controls vulnerabilitySun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote auth…EPSS 2.6%6.4CVE-2008-5117Sun java system identity manager improper input validation vulnerabilityOpen redirect vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to redirect users to arbitr…EPSS 2.6%5.8CVE-2008-0241Sun java system identity manager improper input validation vulnerabilityOpen redirect vulnerability in /idm/user/login.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to r…EPSS 2.7%5.0CVE-2009-1074Sun java system identity manager vulnerabilitySun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to …EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2009-1083), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.