VYPR
Unrated severityNVD Advisory· Published Jan 11, 2008· Updated Apr 23, 2026

CVE-2008-0241

CVE-2008-0241

Description

Open redirect vulnerability in /idm/user/login.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the nextPage parameter.

Affected products

5
  • cpe:2.3:a:sun:java_system_identity_manager:6.0:sp1:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:sun:java_system_identity_manager:6.0:sp1:*:*:*:*:*:*
    • cpe:2.3:a:sun:java_system_identity_manager:6.0:sp2:*:*:*:*:*:*
    • cpe:2.3:a:sun:java_system_identity_manager:6.0:sp3:*:*:*:*:*:*
    • cpe:2.3:a:sun:java_system_identity_manager:7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:java_system_identity_manager:7.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.