Lucene search

K
cveMitreCVE-2009-1934
HistoryJun 05, 2009 - 4:00 p.m.

CVE-2009-1934

2009-06-0516:00:00
CWE-79
mitre
web.nvd.nist.gov
33
cve-2009-1934
cross-site scripting
xss
vulnerability
sun java system web server
gateway error

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.5

Confidence

High

EPSS

0.003

Percentile

70.5%

Cross-site scripting (XSS) vulnerability in the Reverse Proxy Plug-in in Sun Java System Web Server 6.1 before SP11 allows remote attackers to inject arbitrary web script or HTML via the query string in situations that result in a 502 Gateway error.

Affected configurations

Nvd
Node
sunjava_system_web_serverMatch6.1sp10aix
OR
sunjava_system_web_serverMatch6.1sp4aix
OR
sunjava_system_web_serverMatch6.1sp5aix
OR
sunjava_system_web_serverMatch6.1sp6aix
OR
sunjava_system_web_serverMatch6.1sp7aix
OR
sunjava_system_web_serverMatch6.1sp8aix
OR
sunjava_system_web_serverMatch6.1sp9aix
OR
sunone_web_serverMatch6.1aix
OR
sunone_web_serverMatch6.1sp1aix
OR
sunone_web_serverMatch6.1sp2aix
OR
sunone_web_serverMatch6.1sp3aix
Node
sunjava_system_web_serverMatch6.1sp10hp_ux
OR
sunjava_system_web_serverMatch6.1sp4hp_ux
OR
sunjava_system_web_serverMatch6.1sp5hp_ux
OR
sunjava_system_web_serverMatch6.1sp6hp_ux
OR
sunjava_system_web_serverMatch6.1sp7hp_ux
OR
sunjava_system_web_serverMatch6.1sp8hp_ux
OR
sunjava_system_web_serverMatch6.1sp9hp_ux
OR
sunone_web_serverMatch6.1hp_ux
OR
sunone_web_serverMatch6.1sp1hp_ux
OR
sunone_web_serverMatch6.1sp2hp_ux
OR
sunone_web_serverMatch6.1sp3hp_ux
Node
sunjava_system_web_serverMatch6.1sp10linux
OR
sunjava_system_web_serverMatch6.1sp4linux
OR
sunjava_system_web_serverMatch6.1sp5linux
OR
sunjava_system_web_serverMatch6.1sp6linux
OR
sunjava_system_web_serverMatch6.1sp7linux
OR
sunjava_system_web_serverMatch6.1sp8linux
OR
sunjava_system_web_serverMatch6.1sp9linux
OR
sunone_web_serverMatch6.1linux
OR
sunone_web_serverMatch6.1sp1linux
OR
sunone_web_serverMatch6.1sp2linux
OR
sunone_web_serverMatch6.1sp3linux
Node
sunjava_system_web_serverMatch6.1sp10windows
OR
sunjava_system_web_serverMatch6.1sp4windows
OR
sunjava_system_web_serverMatch6.1sp5windows
OR
sunjava_system_web_serverMatch6.1sp6windows
OR
sunjava_system_web_serverMatch6.1sp7windows
OR
sunjava_system_web_serverMatch6.1sp8windows
OR
sunjava_system_web_serverMatch6.1sp9windows
OR
sunone_web_serverMatch6.1windows
OR
sunone_web_serverMatch6.1sp1windows
OR
sunone_web_serverMatch6.1sp2windows
OR
sunone_web_serverMatch6.1sp3windows
Node
sunjava_system_web_serverMatch6.1sp10sparc
OR
sunjava_system_web_serverMatch6.1sp4sparc
OR
sunjava_system_web_serverMatch6.1sp5sparc
OR
sunjava_system_web_serverMatch6.1sp6sparc
OR
sunjava_system_web_serverMatch6.1sp7sparc
OR
sunjava_system_web_serverMatch6.1sp8sparc
OR
sunjava_system_web_serverMatch6.1sp9sparc
OR
sunone_web_serverMatch6.1sparc
OR
sunone_web_serverMatch6.1sp1sparc
OR
sunone_web_serverMatch6.1sp2sparc
OR
sunone_web_serverMatch6.1sp3sparc
Node
sunjava_system_web_serverMatch6.1sp10x86
OR
sunjava_system_web_serverMatch6.1sp4x86
OR
sunjava_system_web_serverMatch6.1sp48x86
OR
sunjava_system_web_serverMatch6.1sp5x86
OR
sunjava_system_web_serverMatch6.1sp6x86
OR
sunjava_system_web_serverMatch6.1sp7x86
OR
sunjava_system_web_serverMatch6.1sp9x86
OR
sunone_web_serverMatch6.1x86
OR
sunone_web_serverMatch6.1sp1x86
OR
sunone_web_serverMatch6.1sp2x86
OR
sunone_web_serverMatch6.1sp3x86
VendorProductVersionCPE
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:sp10:aix:*:*:*:*:*
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:sp4:aix:*:*:*:*:*
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:sp5:aix:*:*:*:*:*
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:sp6:aix:*:*:*:*:*
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:sp7:aix:*:*:*:*:*
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:sp8:aix:*:*:*:*:*
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:sp9:aix:*:*:*:*:*
sunone_web_server6.1cpe:2.3:a:sun:one_web_server:6.1:*:aix:*:*:*:*:*
sunone_web_server6.1cpe:2.3:a:sun:one_web_server:6.1:sp1:aix:*:*:*:*:*
sunone_web_server6.1cpe:2.3:a:sun:one_web_server:6.1:sp2:aix:*:*:*:*:*
Rows per page:
1-10 of 661

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.5

Confidence

High

EPSS

0.003

Percentile

70.5%

Related for CVE-2009-1934