PT-2003-1603 · Sun · Sun One Application Server

Published

2003-06-11

·

Updated

2016-10-18

·

CVE-2003-0412

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Sun ONE Application Server version 7.0
Description: The issue is related to the logging of HTTP requests. Specifically, it does not log the complete URI of a long HTTP request, which could allow remote attackers to hide malicious activities.
Recommendations: For Sun ONE Application Server version 7.0, consider configuring the server to log complete URI information for all HTTP requests to prevent malicious activities from being hidden. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0412

Affected Products

Sun One Application Server