[Japanese]

JVNDB-2010-000042

Cross-site Request Forgery Vulnerability in Oracle iPlanet Web Server

Overview

Oracle iPlanet Web Server (formerly Sun Java System Web Server) contains a cross-site request forgery vulnerability.

Oracle iPlanet Web Server (formerly Sun Java System Web Server) is a web server. Oracle iPlanet Web Server contains a cross-site request forgery vulnerability.

Yoshihiro Ishikawa of LAC reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V2 Severity:
Base Metrics 4.0 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: High
  • Authentication: None
  • Confidentiality Impact: None
  • Integrity Impact: Partial
  • Availability Impact: Partial
Affected Products


Oracle Corporation
  • Oracle iPlanet Web Server prior to 7.0U9

Impact

If a user views a malicious page while logged into the Oracle iPlanet Web Server management console, an arbitrary instance may be stopped.
Solution

[Update the Software]
Update to the latest version according to the information provided by the developer.
Vendor Information

Oracle Corporation
CWE (What is CWE?)

  1. Cross-Site Request Forgery(CWE-352) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2010-3544
References

  1. JVN : JVN#50133036
  2. National Vulnerability Database (NVD) : CVE-2010-3544
  3. US-CERT Technical Cyber Security Alert : TA10-287A
  4. SecurityFocus : 43977
Revision History

  • [2010/10/18]
      Web page published