Sun Java ASP Server Information Disclosure Vulnerability
BID:29540
Info
Sun Java ASP Server Information Disclosure Vulnerability
| Bugtraq ID: | 29540 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-2402 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 04 2008 12:00AM |
| Updated: | Jun 04 2008 12:00AM |
| Credit: | The discoverer of this issue wishes to remain anonymous. |
| Vulnerable: |
Sun Java System Active Server Pages (ASP) Server 4.0.2 Sun Java System Active Server Pages (ASP) Server 4.0.1 Sun Java System Active Server Pages (ASP) Server 4.0 |
| Not Vulnerable: |
Sun Java System Active Server Pages (ASP) Server 4.0.3 |
Discussion
Sun Java ASP Server Information Disclosure Vulnerability
Sun Java ASP Server is prone to an information-disclosure issue because it fails to restrict access to potentially sensitive information.
Attackers can exploit this issue to obtain information that will aid in further attacks.
Java ASP Server 4.0.2 and prior versions are vulnerable.
NOTE: This issue does not affect instances of the server when running on Microsoft Windows.
Sun Java ASP Server is prone to an information-disclosure issue because it fails to restrict access to potentially sensitive information.
Attackers can exploit this issue to obtain information that will aid in further attacks.
Java ASP Server 4.0.2 and prior versions are vulnerable.
NOTE: This issue does not affect instances of the server when running on Microsoft Windows.
Exploit / POC
Sun Java ASP Server Information Disclosure Vulnerability
Attackers can exploit this issue using readily available networking utilities.
Attackers can exploit this issue using readily available networking utilities.
Solution / Fix
Sun Java ASP Server Information Disclosure Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Sun Java System Active Server Pages (ASP) Server 4.0
Sun Java System Active Server Pages (ASP) Server 4.0.1
Sun Java System Active Server Pages (ASP) Server 4.0.2
Solution:
The vendor has released fixes. Please see the references for more information.
Sun Java System Active Server Pages (ASP) Server 4.0
-
Sun Sun Java System Active Server Pages 4.0.3
https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_SMI-Site/en_ US/-/USD/ViewProductDetail-Start?ProductRef=SJASP-4.0.3-OTH-G-TP@CDS-C DS_SMI
Sun Java System Active Server Pages (ASP) Server 4.0.1
-
Sun Sun Java System Active Server Pages 4.0.3
https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_SMI-Site/en_ US/-/USD/ViewProductDetail-Start?ProductRef=SJASP-4.0.3-OTH-G-TP@CDS-C DS_SMI
Sun Java System Active Server Pages (ASP) Server 4.0.2
-
Sun Sun Java System Active Server Pages 4.0.3
https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_SMI-Site/en_ US/-/USD/ViewProductDetail-Start?ProductRef=SJASP-4.0.3-OTH-G-TP@CDS-C DS_SMI
References
Sun Java ASP Server Information Disclosure Vulnerability
References:
References:
- Java System Active Server Pages Homepage (Sun)
- iDefense Security Advisory 06.03.08: Sun Java System Active Server Pages Informa (iDefense Labs
) - Multiple Security Vulnerabilities in Sun Java ASP Server may lead to execution o (Sun)
- Sun Java System Active Server Pages Information Disclosure Vulnerability (iDefense Labs)