Sun Java System Application Server Reverse SSL Proxy Plug-in Man In The Middle Vulnerability
BID:15728
Info
Sun Java System Application Server Reverse SSL Proxy Plug-in Man In The Middle Vulnerability
| Bugtraq ID: | 15728 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2005 12:00AM |
| Updated: | Dec 06 2005 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Sun ONE Application Server 7.0 UR2 Upgrade Standard Sun ONE Application Server 7.0 UR2 Standard Edition Sun ONE Application Server 7.0 UR1 Standard Edition Sun ONE Application Server 7.0 Standard Edition Sun Java System Application Server Enterprise Edition 8.1 2005Q1RHEL2.1/RHEL3 Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 Sun Java System Application Server 7.0 2004Q2 R2 Standard Sun Java System Application Server 7.0 2004Q2 R2 Enterprise Sun Java System Application Server 7.0 2004Q2 R1Standard Sun Java System Application Server 7.0 2004Q2 R1Enterprise Sun Java System Application Server 7.0 Standard Edition Sun Java System Application Server 7.0 Enterprise Edition Sun Java System Application Server 7.0 2004Q2 |
| Not Vulnerable: |
Sun ONE Application Server 7.0 UR7 Standard Edition Sun Java System Application Server 7.0 2004Q2 R3 Standard Sun Java System Application Server 7.0 2004Q2 R3 Enterprise |
Discussion
Sun Java System Application Server Reverse SSL Proxy Plug-in Man In The Middle Vulnerability
Sun Java System Application Server is prone to a man in the middle vulnerability.
This issue arises when the reverse SSL proxy plug-in is used with a supported Web server.
An attacker may exploit this issue to gain access to sensitive contents of encrypted network traffic between a client and a server.
Sun Java System Application Server is prone to a man in the middle vulnerability.
This issue arises when the reverse SSL proxy plug-in is used with a supported Web server.
An attacker may exploit this issue to gain access to sensitive contents of encrypted network traffic between a client and a server.
Exploit / POC
Sun Java System Application Server Reverse SSL Proxy Plug-in Man In The Middle Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Sun Java System Application Server Reverse SSL Proxy Plug-in Man In The Middle Vulnerability
Solution:
Sun has released an advisory (Sun Alert ID: 102012) including fixes to address this issue. Please see the referenced advisory for more information.
Solution:
Sun has released an advisory (Sun Alert ID: 102012) including fixes to address this issue. Please see the referenced advisory for more information.
References
Sun Java System Application Server Reverse SSL Proxy Plug-in Man In The Middle Vulnerability
References:
References:
- Sun Alert ID: 102012 (Sun)