Vulnerabilities > CVE-2010-3514 - Unspecified vulnerability in Oracle SUN products Suite 6.1/7.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Unspecified vulnerability in the Oracle iPlanet Web Server (Sun Java System Web Server) component in Oracle Sun Products Suite 6.1 and 7.0 allows remote attackers to affect integrity via unknown vectors related to Web Container.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description | Oracle Sun Java System Web Server - HTTP Response Splitting. CVE-2010-3514. Webapps exploit for jsp platform |
id | EDB-ID:15290 |
last seen | 2016-02-01 |
modified | 2010-10-20 |
published | 2010-10-20 |
reporter | Roberto Suggi Liverani |
source | https://www.exploit-db.com/download/15290/ |
title | Oracle Sun Java System Web Server - HTTP Response Splitting |
Nessus
NASL family | Web Servers |
NASL id | SUN_JAVA_WEB_SERVER_7_0_9.NASL |
description | According to its self-reported version, the Oracle iPlanet Web Server (formerly known as Sun Java System Web Server) running on the remote host is 7.0.x prior to 7.0.9. It is, therefore, affected by multiple vulnerabilities : - An unspecified file disclosure vulnerability exists in the WebDAV component. (CVE-2010-3512) - An HTTP response splitting vulnerability exists in the web container component due to a failure to sanitize HTTP response headers of CR / LF characters. (CVE-2010-3514) - A cross-site request forgery vulnerability exists in the management console that can allow an attacker to stop an arbitrary server instance. (CVE-2010-3544) - An unspecified flaw exists in the administration component that allows a remote attacker to impact confidentiality and integrity via unknown vectors. (CVE-2010-3545) |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 51138 |
published | 2010-12-13 |
reporter | This script is Copyright (C) 2010-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/51138 |
title | Oracle iPlanet Web Server 7.0.x < 7.0.9 Multiple Vulnerabilities |
code |
|