AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-2402

MEDIUM · CVSS 5 EPSS 11.37%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-06-04 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2008-2402
Severity
MEDIUM
CVSS
5
EPSS
11.37%
Java

Original NVD Description

The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read password hashes and configuration data via direct requests for unspecified documents.