|
Sun Java System Web Server Multiple HTTP Redirect Vulnerabilities
Sun Java System Web Server is prone to multiple vulnerabilities regarding 'redirect' functionality. The vulnerabilities include HTTP-response splitting, HTTP-header injection, and unauthorized access to system resources. An attacker may exploit the HTTP-response-splitting vulnerability to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust. Attackers typically exploit HTTP-header-injection issues to inject arbitrary cookie attributes into a session cookie. Since session IDs are usually stored in cookie form, an attacker can inject arbitrary cookie data attributes into a session cookie and then launch various attacks on active web sessions. |
|
|
Privacy Statement |