CVE-2007-4164

HIGH
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

CRLF injection vulnerability in the redirect feature in Sun Java System Web Server 6.1 and 7.0 before 20070802, when the redirect Server Application Function (SAF) uses the url-prefix parameter and escape is disabled, or an Error directive uses the url-prefix parameter in obj.conf, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks.

References

http://secunia.com/advisories/26326

http://sunsolve.sun.com/search/document.do?assetkey=1-26-103003-1

http://www.securityfocus.com/bid/25190

http://www.securitytracker.com/id?1018504

http://www.vupen.com/english/advisories/2007/2766

https://exchange.xforce.ibmcloud.com/vulnerabilities/35783

Details

Source: MITRE

Published: 2007-08-07

Updated: 2017-07-29

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

Tenable Plugins

View all (12 total)

IDNameProductFamilySeverity
107932Solaris 10 (x86) : 125438-22NessusSolaris Local Security Checks
high
107796Solaris 10 (x86) : 116649-25NessusSolaris Local Security Checks
high
107431Solaris 10 (sparc) : 125437-22NessusSolaris Local Security Checks
high
107295Solaris 10 (sparc) : 116648-25NessusSolaris Local Security Checks
high
27039Solaris 9 (x86) : 125438-22NessusSolaris Local Security Checks
high
27023Solaris 9 (sparc) : 125437-22NessusSolaris Local Security Checks
high
27010Solaris 8 (sparc) : 125437-22NessusSolaris Local Security Checks
high
27000Solaris 10 (x86) : 125438-22 (deprecated)NessusSolaris Local Security Checks
high
26988Solaris 10 (sparc) : 125437-22 (deprecated)NessusSolaris Local Security Checks
high
23519Solaris 9 (sparc) : 116648-25NessusSolaris Local Security Checks
high
23381Solaris 8 (sparc) : 116648-25NessusSolaris Local Security Checks
high
22946Solaris 10 (sparc) : 116648-25 (deprecated)NessusSolaris Local Security Checks
high