4.3
CVSSv2

CVE-2010-3514

Published: 14/10/2010 Updated: 11/11/2010
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Unspecified vulnerability in the Oracle iPlanet Web Server (Sun Java System Web Server) component in Oracle Sun Products Suite 6.1 and 7.0 allows remote malicious users to affect integrity via unknown vectors related to Web Container.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle sun products suite 7.0

oracle sun products suite 6.1

Exploits

Description Security-Assessmentcom discovered that is possible to successfully perform an HTTP Response Splitting attack against applications served by Sun Java System Web Server The vulnerability can be exploited if user supplied input is used to generate the value of an HTTP header, as shown in the testjsp page below: testjsp – Source Cod ...