5

CVE-2009-2445

Exploit
Oracle iPlanet Web Server (formerly Sun Java System Web Server or Sun ONE Web Server) 6.1 before SP12, and 7.0 through Update 6, when running on Windows, allows remote attackers to read arbitrary JSP files via an alternate data stream syntax, as demonstrated by a .jsp::$DATA URI.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sun ≫ Java System Web Server Version 6.1 Edition windows
Sun ≫ Java System Web Server Version 6.1 Update sp10 Edition windows
Sun ≫ Java System Web Server Version 6.1 Update sp11 Edition windows
Sun ≫ Java System Web Server Version 6.1 Update sp4 Edition windows
Sun ≫ Java System Web Server Version 6.1 Update sp5 Edition windows
Sun ≫ Java System Web Server Version 6.1 Update sp6 Edition windows
Sun ≫ Java System Web Server Version 6.1 Update sp7 Edition windows
Sun ≫ Java System Web Server Version 6.1 Update sp8 Edition windows
Sun ≫ Java System Web Server Version 6.1 Update sp9 Edition windows
Sun ≫ Java System Web Server Version 7.0 Update update_5 Edition windows
Sun ≫ Java System Web Server Version 7.0 Update update_6 Edition windows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.52% 0.828
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://isowarez.de/SunOne_Webserver.txt
Exploit
http://jvn.jp/en/jp/JVN47124169/index.html
http://jvndb.jvn.jp/jvndb/JVNDB-2009-002069
http://secunia.com/advisories/35701
Vendor Advisory
http://securitytracker.com/id?1022511
Exploit
http://sunsolve.sun.com/search/document.do?assetkey=1-26-266429-1
Vendor Advisory
http://www.osvdb.org/55655
http://www.vupen.com/english/advisories/2009/1786
Vendor Advisory