Description: Sun has acknowledged a vulnerability in Sun Java System Web Server, which can be exploited by malicious users to bypass certain security restriction.
If a secure non-root server instance is set up by an admin server running as root, an unspecified error can be exploited to gain access to the web server instance using a revoked client certificate even if the server instance has a valid Certificate Revocation List (CRL) file installed.
Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, scan using the Network Software Inspector.
Solution: Install Service Pack 7 for Sun Java System Web Server 6.1 or apply patches.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.