Vulnerabilities > CVE-2000-1247 - Configuration vulnerability in Apache Jserv 1.1.2
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
References
- http://archive.apache.org/dist/java/java.apache.org-www.tar.gz
- http://archive.apache.org/dist/java/java.apache.org-www.tar.gz
- http://marc.info/?l=java-apache-users&m=97036799917909&w=2
- http://marc.info/?l=java-apache-users&m=97036799917909&w=2
- http://securityreason.com/securityalert/8412
- http://securityreason.com/securityalert/8412
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51946
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51946