PT-2009-3887 · Oracle · Sun Java System Delegated Administrator
Published
2009-04-23
·
Updated
2018-10-10
·
CVE-2009-1357
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Sun Java System Delegated Administrator versions 6.2 through 6.4
Description
The issue concerns a CRLF injection vulnerability. This vulnerability allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the
HELP PAGE parameter in the da/DA/Login endpoint.Recommendations
For versions 6.2 through 6.4, consider restricting access to the da/DA/Login endpoint until a fix is available, and avoid using the
HELP PAGE parameter in this endpoint to minimize the risk of exploitation.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sun Java System Delegated Administrator