PT-2001-1552 · Oracle · Iplanet Web Server Enterprise Edition
Published
2001-07-02
·
Updated
2008-09-05
·
CVE-2001-0327
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
iPlanet Web Server Enterprise Edition versions 4.1 and earlier
Description
The issue allows remote attackers to retrieve sensitive data from memory allocation pools or cause a denial of service. This is achieved via a URL-encoded Host: header in the HTTP request, which reveals memory in the Location: header returned by the server.
Recommendations
For iPlanet Web Server Enterprise Edition versions 4.1 and earlier, update to a version later than 4.1 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Iplanet Web Server Enterprise Edition