Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Sun Java System Web Server Multiple HTTP Redirect Vulnerabilities

Sun Java System Web Server is prone to multiple vulnerabilities regarding 'redirect' functionality. The vulnerabilities include HTTP-response splitting, HTTP-header injection, and unauthorized access to system resources.

An attacker may exploit the HTTP-response-splitting vulnerability to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust.

Attackers typically exploit HTTP-header-injection issues to inject arbitrary cookie attributes into a session cookie. Since session IDs are usually stored in cookie form, an attacker can inject arbitrary cookie data attributes into a session cookie and then launch various attacks on active web sessions.







 

Privacy Statement
Copyright 2009, SecurityFocus