SAP Web Application Server HTTP Response Splitting Vulnerability
BID:15360
CVE-2005-3633 |Info
SAP Web Application Server HTTP Response Splitting Vulnerability
| Bugtraq ID: | 15360 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 09 2005 12:00AM |
| Updated: | Nov 09 2005 12:00AM |
| Credit: | Leandro Meiners <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
SAP Web Application Server 7.0 SAP Web Application Server 6.40 SAP Web Application Server 6.20 SAP Web Application Server 6.10 |
| Not Vulnerable: | |
Discussion
SAP Web Application Server HTTP Response Splitting Vulnerability
SAP Web Application Server is prone to an HTTP response splitting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
A remote attacker may exploit this vulnerability to influence or misrepresent how Web content is served, cached or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust.
This issue only affects the BSP runtime of SAP WAS.
SAP Web Application Server is prone to an HTTP response splitting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
A remote attacker may exploit this vulnerability to influence or misrepresent how Web content is served, cached or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust.
This issue only affects the BSP runtime of SAP WAS.
Exploit / POC
SAP Web Application Server HTTP Response Splitting Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
SAP Web Application Server HTTP Response Splitting Vulnerability
Solution:
The vendor has released solutions and patch information regarding this issue. Users are advised to contact the vendor for further information.
Solution:
The vendor has released solutions and patch information regarding this issue. Users are advised to contact the vendor for further information.
References
SAP Web Application Server HTTP Response Splitting Vulnerability
References:
References:
- SAP Homepage (SAP)
- CYBSEC - Security Advisory: HTTP Response Splitting in SAP WAS (Leandro Meiners
)