PT-2001-1927 · Oracle · Iplanet Web Server Enterprise Edition
Published
2001-10-12
·
Updated
2017-12-19
·
CVE-2001-0746
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
iPlanet Web Server Enterprise Edition versions 4.1 and earlier
Description:
A buffer overflow issue in the Web Publisher component allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with methods such as
GETPROPERTIES or GETATTRIBUTENAMES.Recommendations:
For iPlanet Web Server Enterprise Edition versions 4.1 and earlier, consider restricting access to the Web Publisher component until a fix is available. As a temporary workaround, limit the length of URIs that can be processed by the server to prevent exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Iplanet Web Server Enterprise Edition