PT-2001-1927 · Oracle · Iplanet Web Server Enterprise Edition

Published

2001-10-12

·

Updated

2017-12-19

·

CVE-2001-0746

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: iPlanet Web Server Enterprise Edition versions 4.1 and earlier
Description: A buffer overflow issue in the Web Publisher component allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with methods such as GETPROPERTIES or GETATTRIBUTENAMES.
Recommendations: For iPlanet Web Server Enterprise Edition versions 4.1 and earlier, consider restricting access to the Web Publisher component until a fix is available. As a temporary workaround, limit the length of URIs that can be processed by the server to prevent exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0746

Affected Products

Iplanet Web Server Enterprise Edition