Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bug on CVE-2009-2704 and CVE-2009-2705 in SiteMinder J2EE #7002

Closed
gobiltd opened this issue Oct 1, 2024 · 2 comments
Closed

Bug on CVE-2009-2704 and CVE-2009-2705 in SiteMinder J2EE #7002

gobiltd opened this issue Oct 1, 2024 · 2 comments

Comments

@gobiltd
Copy link

gobiltd commented Oct 1, 2024

Describe the bug
As per NVD description , these CVE-2009-2704 and CVE-2009-2705 should be valid if we have combination of cpe:2.3:a:sun:j2ee:::::::: and cpe:2.3:a:broadcom:siteminder:::::::: in scanned project. However, the CVE-2009-2704 and CVE-2009-2705 is getting reported even if we have only one of the matching CPE (cpe:2.3:a:sun:j2ee::::::::) related jar

Version of dependency-check used
The problem occurs using version 8.2.1 of the CLI.

To Reproduce
Steps to reproduce the behavior:

  • Download any jar named *j2ee.jar and run the OWASP DC CLI - 8.2.1.
  • Reporting CVE-2009-2705 and CVE-2009-2704 will be reported due to CPE "cpe:2.3:a:sun:j2ee::::::::"

Expected behavior

  • CVE-2009-2705 and CVE-2009-2704 configuration having AND condition (multiple CPEs assigned), but with one CPE "cpe:2.3:a:sun:j2ee::::::::" also artifact is listing these CVE's.
@gobiltd gobiltd added the bug label Oct 1, 2024
@jeremylong
Copy link
Owner

The AND/OR configurations have not been implemented as ODC does not always have the information required to evaluate these.

@aikebah
Copy link
Collaborator

aikebah commented Oct 2, 2024

Also note that ODC 8.2.1 is outdated and unsupported. You should update to 10.x

@aikebah aikebah closed this as not planned Won't fix, can't repro, duplicate, stale Oct 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants