Vulnerabilities > CVE-1999-1527 - Unspecified vulnerability in SUN Forte and Netbeans Developer

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
sun
nessus

Summary

Internal HTTP server in Sun Netbeans Java IDE in Netbeans Developer 3.0 Beta and Forte Community Edition 1.0 Beta does not properly restrict access to IP addresses as specified in its configuration, which allows arbitrary remote attackers to access the server.

Vulnerable Configurations

Part Description Count
Application
Sun
2

Nessus

NASL familyWeb Servers
NASL idNETBEANS.NASL
descriptionThe remote host is running NetBeans (recently renamed to 'Forte') Java IDE. There is a bug in this version that allows anyone to browse the files on this system. This plugin has been deprecated. Webmirror3 (plugin ID 10662) will identify a browsable directory.
last seen2018-07-18
modified2018-07-16
plugin id10149
published1999-11-24
reporterTenable
sourcehttps://www.tenable.com/plugins/index.php?view=single&id=10149
titleSun NetBeans Java IDE HTTP Server IP Restriction Bypass Arbitrary File/Directory Access (deprecated)