---------------------------------------------------------------------- Secunia CSI + Microsoft SCCM ----------------------- = Extensive Patch Management http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ ---------------------------------------------------------------------- TITLE: Sun Java System Communications Express Address Book Vulnerability SECUNIA ADVISORY ID: SA39436 VERIFY ADVISORY: http://secunia.com/advisories/39436/ DESCRIPTION: A vulnerability has been reported in Sun Java System Communications Express, which can be exploited by malicious users to manipulate certain data. The vulnerability is caused due to an unspecified error in the Address Book component and can be exploited to inject custom XML data. No further information is currently available. SOLUTION: Apply patches. -- SPARC Platform -- Sun Java System Communications Express 6.3: Apply patch 122793-31 or later. -- x86 Platform -- Sun Java System Communications Express 6.3: Apply patch 122794-31 or later. -- Linux Platform -- Sun Java System Communications Express 6.3: Apply patch 122795-31 or later. PROVIDED AND/OR DISCOVERED BY: It is currently unclear who reported this vulnerability as the Oracle Critical Patch Update for April 2010 only provides a bundled list of credits. This section will be updated when/if the original reporter provides more information. CHANGELOG: 2010-04-16: Updated the description of the vulnerability. ORIGINAL ADVISORY: http://sunsolve.sun.com/search/document.do?assetkey=1-66-276630-1 http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------