PT-2009-1145 · Sun · Sunone/Iplanet Web Server

Published

2009-06-01

·

Updated

2026-05-28

·

CVE-2004-2763

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Sun ONE/iPlanet Web Server versions 4.1 SP1 through 4.1 SP12 Sun ONE/iPlanet Web Server versions 6.0 SP1 through 6.0 SP5
Description The default configuration of the web server responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.
Recommendations For Sun ONE/iPlanet Web Server versions 4.1 SP1 through 4.1 SP12, disable the HTTP TRACE request to prevent cross-site tracing attacks. For Sun ONE/iPlanet Web Server versions 6.0 SP1 through 6.0 SP5, disable the HTTP TRACE request to prevent cross-site tracing attacks.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2004-2763

Affected Products

Sunone/Iplanet Web Server