Note: This is an archival copy of Security Sun Alert 201173 as previously published on http://sunsolve.sun.com.
Latest version of this security advisory is available from http://support.oracle.com as Sun Alert 1000887.1.
Article ID : 1000887.1
Article Type : Sun Alerts (SURE)
Last reviewed : 2010-01-19
Audience : PUBLIC
Copyright Notice: Copyright © 2010, Oracle Corporation and/or its affiliates.

Proxy Authentication to Sun ONE Calendar Server May Fails if Portal Display Preferences Are Changed



Category
Security

Release Phase
Resolved

Bug Id
5014142

Date of Resolved Release
21-JUL-2004

Impact

A security vulnerability in Sun Java System Portal Server Software 6.2 may allow a user to gain Calendar Server administrator credentials if the user changes the display options to select a non-default view. With these credentials, a user's session has unrestricted access to the calendar data and hence manipulation of that data. Such manipulation could include, but is not limited to: the deletion, creation, and modification of users, user information, calendar entries, and historical data.


Contributing Factors

This issue can occur in the following releases:

SPARC Platform

  • Sun Java System Portal Server Software 6.2 (for Solaris 8 and Solaris 9) without patch 116856-10

X86 Platform

  • Sun Java System Portal Server Software 6.2 (for Solaris 8 and Solaris 9) without patch 117757-09

The described issue only occurs if the following conditions are true:

  • Admin Proxy Authentication is configured on the Calendar Server
  • Calendar access is via the "Portal" communication channel and not the "Unified Web Client" or the "Calendar Web Client"

Note: This issue only affects the calendar component. The calendar configuration information is not affected.


Symptoms

There are no reliable symptoms that would indicate the described issue has been exploited to gain access to calendar data.


Workaround

To work around the described issue, do not allow end users the ability to edit the calendar channels "calendar" or "view" display profile properties when Admin Proxy Authentication is enabled.

For additional information on Administrator Proxy Authentication, see http://docs.sun.com/source/816-6748-10/comm_config.html#wp34042.


Resolution

This issue is addressed in the following releases:

SPARC Platform

  • Sun Java System Portal Server Software 6.2 with patch 116856-10 or later

X86 Platform

  • Sun Java System Portal Server Software 6.2 with patch 117757-09 or later


Modification History

Product
Sun Java System Portal Server 6.2

References

116856-10
117757-09




Attachments
This solution has no attachment