PT-2000-1563 · Sun · Sun Java Web Server

Published

2000-07-12

·

Updated

2008-09-10

·

CVE-2000-0629

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sun Java web server versions 2.0 and earlier
Description The default configuration of the Sun Java web server allows remote attackers to execute arbitrary commands. This is achieved by uploading Java code to the server via "board.html", then directly calling the JSP compiler servlet.
Recommendations For Sun Java web server versions 2.0 and earlier, consider disabling the JSP compiler servlet as a temporary workaround until a patch is available. Restrict access to the "board.html" page to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-0629

Affected Products

Sun Java Web Server