Lucene search

K
cveMitreCVE-2007-4164
HistoryAug 07, 2007 - 10:17 a.m.

CVE-2007-4164

2007-08-0710:17:00
mitre
web.nvd.nist.gov
34
security
vulnerability
crlf injection
sun java system web server
http response splitting
nvd
cve-2007-4164

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.6

Confidence

Low

EPSS

0.037

Percentile

91.9%

CRLF injection vulnerability in the redirect feature in Sun Java System Web Server 6.1 and 7.0 before 20070802, when the redirect Server Application Function (SAF) uses the url-prefix parameter and escape is disabled, or an Error directive uses the url-prefix parameter in obj.conf, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks.

Affected configurations

Nvd
Node
sunjava_system_web_serverMatch6.1
OR
sunjava_system_web_serverMatch6.1sp1
OR
sunjava_system_web_serverMatch6.1sp2
OR
sunjava_system_web_serverMatch6.1sp3
OR
sunjava_system_web_serverMatch6.1sp4
OR
sunjava_system_web_serverMatch6.1sp5
OR
sunjava_system_web_serverMatch6.1sp6
OR
sunjava_system_web_serverMatch6.1sp7
OR
sunjava_system_web_serverMatch7.0
VendorProductVersionCPE
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:*:*:*:*:*:*:*
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:sp1:*:*:*:*:*:*
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:sp2:*:*:*:*:*:*
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:sp3:*:*:*:*:*:*
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:sp4:*:*:*:*:*:*
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:sp5:*:*:*:*:*:*
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:sp6:*:*:*:*:*:*
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:sp7:*:*:*:*:*:*
sunjava_system_web_server7.0cpe:2.3:a:sun:java_system_web_server:7.0:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.6

Confidence

Low

EPSS

0.037

Percentile

91.9%

Related for CVE-2007-4164