Fujitsu Jasmine2000 Enterprise Edition WebLink HTTP Response Splitting Vulnerability
BID:33832
Info
Fujitsu Jasmine2000 Enterprise Edition WebLink HTTP Response Splitting Vulnerability
| Bugtraq ID: | 33832 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 19 2009 12:00AM |
| Updated: | Feb 19 2009 04:17PM |
| Credit: | Fujitsu |
| Vulnerable: |
Fujitsu Jasmine2000 Enterprise Edition 0 |
| Not Vulnerable: | |
Discussion
Fujitsu Jasmine2000 Enterprise Edition WebLink HTTP Response Splitting Vulnerability
Fujitsu Jasmine2000 Enterprise Edition is prone to an HTTP response-splitting vulnerability because it fails to sufficiently sanitize user-supplied data.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
Fujitsu Jasmine2000 Enterprise Edition is prone to an HTTP response-splitting vulnerability because it fails to sufficiently sanitize user-supplied data.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
Exploit / POC
Fujitsu Jasmine2000 Enterprise Edition WebLink HTTP Response Splitting Vulnerability
Attackers can leverage the issue to corrupt a cached version of a page or entice an unsuspecting victim into following a malicious URI.
Attackers can leverage the issue to corrupt a cached version of a page or entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Fujitsu Jasmine2000 Enterprise Edition WebLink HTTP Response Splitting Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
References
Fujitsu Jasmine2000 Enterprise Edition WebLink HTTP Response Splitting Vulnerability
References:
References: