PT-2006-2076 · Sap · Sap Web Application Server Kernel

Publicado

2006-03-07

·

Atualizado

2018-10-18

·

CVE-2006-1039

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions SAP Web Application Server (WebAS) Kernel versions prior to 7.0
Description The issue allows remote attackers to inject arbitrary bytes into the HTTP response, potentially obtaining sensitive authentication information or having other impacts. This can be achieved by sending a ";%20" followed by encoded HTTP headers.
Recommendations For versions prior to 7.0, update to version 7.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive authentication information to minimize the risk of exploitation.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-1039

Produtos afetados

Sap Web Application Server Kernel