SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Welcome to SecurityTracker!
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Application (Web Server/CGI)  >  Sun Java Application Server (Sun ONE) Vendors:  Sun
Sun Java Application Server Lets Remote Users Conduct HTTP Request Smuggling Attacks
SecurityTracker Alert ID:  1017322
SecurityTracker URL:  http://securitytracker.com/id?1017322
CVE Reference:  CVE-2006-6276   (Links to External Site)
Updated:  Feb 27 2007
Original Entry Date:  Dec 1 2006
Impact:  Modification of user information
Fix Available:  Yes   Vendor Confirmed:  Yes  
Advisory:  Sun Alert
Version(s): 7, 8.1 2005Q1, 8.1 2005Q1 Update Release 1
Description:  A vulnerability was reported in Sun Java Application Server. A remote user may be able to conduct HTTP request smuggling attacks.

If the Sun Java System Web Server is used in conjunction with the Sun Java Application Server and if there is an input validation vulnerability in the web server or one of its applications, then a remote user can use HTTP request smuggling techniques to hijack a target user's request or conduct a variation of a cross-site scripting attack against a target user.

A remote user can send multiple HTTP requests with specially crafted HTTP headers to the target server via the proxy/gateway server. The requests may be interpreted differently by the target server than by the proxy/gateway server. As a result, unexpected results may occur. A remote user may be able to poison an intermediate cache, bypass application-level security features within an intermediate proxy/gateway server, or conduct cross-site scripting attacks against target users.

Impact:  A remote user may be able to poison an intermediate cache, bypass application-level security features within an intermediate proxy/gateway server, or conduct cross-site scripting attacks against target users.
Solution:  Sun has issued the following fixes.

SPARC Platform

* Sun ONE Application Server 7 without Update 8
* Sun Java System Application Server 7 2004Q2 witout Update 4
* Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 without (file-based) patch 119169-02 or (SVR4) patch 119166-09
* Sun Java System Application Server Platform Edition 8.1 2005 Q1 without (file-based) patch 119173-01

x86 Platform

* Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 without (file-based) patch 119170-02 or (SVR4) patch 119167-09
* Sun Java System Application Server Platform Edition 8.1 2005 Q1 without (file-based) patch 119174-01

Linux Platform

* Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 without (file-based) patch 119171-02 or (Pkg) patch 119168-09
* Sun Java System Application Server Platform Edition 8.1 2005 Q1 without (file-based) patch 119175-01

Windows Platform

* Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 without (file based) patch 119172-07 or (native) patch 121528-01
* Sun Java System Application Server Platform Edition 8.1 2005 Q1 without (file based) patch 119176-01

HP-UX Platform

* Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 with (native) patch 121514-01 or later

The Sun advisory is available at:

http://sunsolve.sun.com/search/document.do?assetkey=1-26-102733-1

Vendor URL:  sunsolve.sun.com/search/document.do?assetkey=1-26-102733-1 (Links to External Site)
Cause:  State error
Underlying OS:  Linux (Any), UNIX (HP/UX), UNIX (Solaris - SunOS), Windows (Any)

Message History:   None.


 Source Message Contents

Date:  Fri, 1 Dec 2006 00:40:34 -0500
Subject:  Security Vulnerability With HTTP Requests in Sun Java System Server(s)

 
 
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102733-1
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2006, SecurityGlobal.net LLC