Vulnerabilities > CVE-2010-3544 - Unspecified vulnerability in Oracle SUN products Suite 7.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN oracle
nessus
Summary
Unspecified vulnerability in the Oracle iPlanet Web Server (Sun Java System Web Server) component in Oracle Sun Products Suite 7.0 allows remote attackers to affect integrity and availability via unknown vectors related to Administration. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable source that this is cross-site request forgery (CSRF) that allows remote attackers to stop an instance via the management console.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Web Servers |
NASL id | SUN_JAVA_WEB_SERVER_7_0_9.NASL |
description | According to its self-reported version, the Oracle iPlanet Web Server (formerly known as Sun Java System Web Server) running on the remote host is 7.0.x prior to 7.0.9. It is, therefore, affected by multiple vulnerabilities : - An unspecified file disclosure vulnerability exists in the WebDAV component. (CVE-2010-3512) - An HTTP response splitting vulnerability exists in the web container component due to a failure to sanitize HTTP response headers of CR / LF characters. (CVE-2010-3514) - A cross-site request forgery vulnerability exists in the management console that can allow an attacker to stop an arbitrary server instance. (CVE-2010-3544) - An unspecified flaw exists in the administration component that allows a remote attacker to impact confidentiality and integrity via unknown vectors. (CVE-2010-3545) |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 51138 |
published | 2010-12-13 |
reporter | This script is Copyright (C) 2010-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/51138 |
title | Oracle iPlanet Web Server 7.0.x < 7.0.9 Multiple Vulnerabilities |
code |
|
References
- http://jvn.jp/en/jp/JVN50133036/index.html
- http://jvn.jp/en/jp/JVN50133036/index.html
- http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000042.html
- http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000042.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html
- http://www.us-cert.gov/cas/techalerts/TA10-287A.html
- http://www.us-cert.gov/cas/techalerts/TA10-287A.html