ID

VAR-E-200911-0275


CVE

cve_id:CVE-2009-2631

Trust: 0.3

sources: BID: 37152

TITLE

Same-origin policy bypass vulnerabilities in several VPN

Trust: 0.6

sources: EDBNET: 67645

AFFECTED PRODUCTS

vendor:nortelmodel:networks callpilot 1002rpscope: - version: -

Trust: 0.6

vendor:sunmodel:java system portal serverscope:eqversion:6.3.1

Trust: 0.3

vendor:sunmodel:java system portal serverscope:eqversion:7.2

Trust: 0.3

vendor:sunmodel:java system portal serverscope:eqversion:7.1

Trust: 0.3

vendor:sunmodel:java system portal serverscope:eqversion:7.0

Trust: 0.3

vendor:sunmodel:java system portal serverscope:eqversion:7

Trust: 0.3

vendor:stonesoftmodel:stonegate ssl vpn enginescope:eqversion:1.4

Trust: 0.3

vendor:stonesoftmodel:stonegate ssl vpn enginescope:eqversion:1.3.1

Trust: 0.3

vendor:stonesoftmodel:stonegate ssl vpn enginescope:eqversion:1.1

Trust: 0.3

vendor:sonicwallmodel:ssl-vpnscope:eqversion:40003.55

Trust: 0.3

vendor:sonicwallmodel:ssl-vpnscope:eqversion:40003.54

Trust: 0.3

vendor:sonicwallmodel:ssl-vpnscope:eqversion:20003.55

Trust: 0.3

vendor:sonicwallmodel:ssl-vpnscope:eqversion:20003.54

Trust: 0.3

vendor:sonicwallmodel:ssl-vpnscope:eqversion:2003.09

Trust: 0.3

vendor:sonicwallmodel:ssl-vpnscope:eqversion:2003.08

Trust: 0.3

vendor:sonicwallmodel:ssl-rxscope:eqversion:4.0.18

Trust: 0.3

vendor:sonicwallmodel:ssl-r6scope:eqversion:4.0.18

Trust: 0.3

vendor:sonicwallmodel:ssl-r3scope:eqversion:4.0.18

Trust: 0.3

vendor:sonicwallmodel:ssl-rscope:eqversion:4.0.18

Trust: 0.3

vendor:sonicwallmodel:ssl vpnscope:eqversion:2002.1

Trust: 0.3

vendor:sonicwallmodel:ssl vpnscope:eqversion:1.33

Trust: 0.3

vendor:sonicwallmodel:ssl vpnscope:eqversion:2.5

Trust: 0.3

vendor:nortelmodel:networks callpilot 703tscope: - version: -

Trust: 0.3

vendor:nortelmodel:networks callpilot 600rscope: - version: -

Trust: 0.3

vendor:nortelmodel:networks callpilot 202iscope: - version: -

Trust: 0.3

vendor:nortelmodel:networks callpilot 201iscope: - version: -

Trust: 0.3

vendor:nortelmodel:networks callpilot 1005rscope: - version: -

Trust: 0.3

vendor:junipermodel:secure accessscope:eqversion:7000

Trust: 0.3

vendor:junipermodel:secure accessscope:eqversion:65000

Trust: 0.3

vendor:junipermodel:secure access spscope:eqversion:60006000

Trust: 0.3

vendor:junipermodel:secure accessscope:eqversion:600050000

Trust: 0.3

vendor:junipermodel:secure accessscope:eqversion:45000

Trust: 0.3

vendor:junipermodel:secure accessscope:eqversion:400030000

Trust: 0.3

vendor:junipermodel:secure accessscope:eqversion:25000

Trust: 0.3

vendor:junipermodel:secure accessscope:eqversion:20000

Trust: 0.3

vendor:junipermodel:sa700 ssl vpnscope:eqversion:0

Trust: 0.3

vendor:citrixmodel:netscaler access gateway enterprise editionscope:eqversion:9.0

Trust: 0.3

vendor:citrixmodel:netscaler access gateway enterprise editionscope:eqversion:8.1

Trust: 0.3

vendor:citrixmodel:access gateway enterprise editionscope:eqversion:9.1

Trust: 0.3

vendor:citrixmodel:access gateway enterprise editionscope:eqversion:9.0

Trust: 0.3

vendor:citrixmodel:access gateway advanced editionscope:eqversion:4.5.5

Trust: 0.3

vendor:citrixmodel:access gateway advanced edition hf2scope:eqversion:4.5

Trust: 0.3

vendor:citrixmodel:access gateway advanced editionscope:eqversion:4.5

Trust: 0.3

vendor:ciscomodel:clientless ssl vpnscope:eqversion:0

Trust: 0.3

vendor:ciscomodel:adaptive security appliancescope:eqversion:8.2.13

Trust: 0.3

vendor:ciscomodel:adaptive security appliancescope:eqversion:8.2.1

Trust: 0.3

vendor:ciscomodel:adaptive security appliancescope:eqversion:8.1.2

Trust: 0.3

vendor:ciscomodel:adaptive security appliancescope:eqversion:8.0.211

Trust: 0.3

vendor:ciscomodel:adaptive security appliancescope:eqversion:8.1.2.25

Trust: 0.3

vendor:ciscomodel:adaptive security appliancescope:eqversion:8.1(2)19

Trust: 0.3

vendor:ciscomodel:adaptive security appliancescope:eqversion:8.1(2)14

Trust: 0.3

vendor:ciscomodel:adaptive security appliancescope:eqversion:8.0.4.34

Trust: 0.3

vendor:ciscomodel:adaptive security appliancescope:eqversion:8.0(4)

Trust: 0.3

vendor:ciscomodel:adaptive security appliancescope:eqversion:8.0

Trust: 0.3

vendor:ciscomodel:adaptive security appliancescope:eqversion:7.2.2.34

Trust: 0.3

vendor:ciscomodel:adaptive security appliancescope:eqversion:7.2

Trust: 0.3

vendor:ciscomodel:adaptive security appliancescope:eqversion:7.1.2.61

Trust: 0.3

vendor:ciscomodel:adaptive security appliancescope:eqversion:7.1

Trust: 0.3

sources: BID: 37152

EXPLOIT

Vulnerabilities in several clientless SSL VPN products have been reported.

Gathering authentication cookies etc. is reportedly possible.
At time of writing US-CERT's advisory lists the status of about 90 vendors.

US-CERT Vulnerability Note VU#261869:
http://www.kb.cert.org/vuls/id/261869
Severity metric is remarkable high: 45,00.

This issue is CVE-2009-2631.

Juha-Matti

Trust: 0.6

sources: EDBNET: 67645

PRICE

free

Trust: 0.6

sources: EDBNET: 67645

TYPE

Design Error

Trust: 0.3

sources: BID: 37152

EXTERNAL IDS

db:CERT/CCid:VU#261869

Trust: 0.9

db:EDBNETid:67645

Trust: 0.6

db:NVDid:CVE-2009-2631

Trust: 0.3

db:BIDid:37152

Trust: 0.3

sources: BID: 37152 // EDBNET: 67645

REFERENCES

url:https://www.intelligentexploit.com

Trust: 0.6

url:http://seclists.org/fulldisclosure/2006/jun/238

Trust: 0.3

url:http://support.nortel.com/go/main.jsp?cscat=bltndetail&id=984744

Trust: 0.3

url:http://www.stonesoft.com/en/support/security_advisories/2009_03_12.html

Trust: 0.3

url:http://kb.juniper.net/kb15799

Trust: 0.3

url:http://www.kb.cert.org/vuls/id/261869

Trust: 0.3

url:http://support.citrix.com/article/ctx123610

Trust: 0.3

url:http://blogs.sun.com/security/entry/portal_server_is_not_vulnerable

Trust: 0.3

sources: BID: 37152 // EDBNET: 67645

SOURCES

db:BIDid:37152
db:EDBNETid:67645

LAST UPDATE DATE

2022-07-27T10:01:41.702000+00:00


SOURCES UPDATE DATE

db:BIDid:37152date:2009-12-16T13:53:00

SOURCES RELEASE DATE

db:BIDid:37152date:2009-11-30T00:00:00
db:EDBNETid:67645date:2009-12-10T00:00:00