JSCI SSO URI Pattern Matching Access...

- AV AC AU C I A
发布: 2003-08-06
修订: 2025-04-13

JSCI SSO has been reported prone to an access validation vulnerability under certain circumstances. The issue presents itself in pattern-matching tags contained in JSCI SSO configuration files; these tags are used when controlling access to Java applications. It has been reported that these pattern-matching tags match an entire URI rather than the relative path to the secured Java application. This may mean that if the protected Java application is moved and has a different context root, JSCI SSO will not protect it.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息