Security Vulnerability in Sun Java System Web Server May Allow Unauthorized Access to Host Data With Certain URLs



Category :Security
Release Phase :Resolved
Product :Sun Java System Web Server 6.0 Service Pack 10
Sun Java System Web Server 6.1
Sun Java System Web Server 6.0 Service Pack 8  
Bug Id :6429293  
Date of Resolved Release :15-MAR-2007 


Impact

A security vulnerability in the Sun Java System Web Server may allow a local or remote user to gain unauthorized access to data stored on the host running the Sun Java System Web Server under certain conditions.


Contributing Factors

This issue can occur in the following releases:

SPARC Platform

  • Sun Java System Web Server 6.0 without Service Pack 11
  • Sun Java System Web Server 6.1 without Service Pack 7
  • Sun Java System Web Server 6.1 without patch 116648-19

x86 Platform

  • Sun Java System Web Server 6.1 without Service Pack 7
  • Sun Java System Web Server 6.1 without patch 116649-19

Linux Platform

  • Sun Java System Web Server 6.0 without Service Pack 11
  • Sun Java System Web Server 6.1 without Service Pack 7
  • Sun Java System Web Server 6.1 without patch 118202-11

AIX Platform

  • Sun Java System Web Server 6.0 without Service Pack 11
  • Sun Java System Web Server 6.1 without Service Pack 7

HP-UX Platform

  • Sun Java System Web Server 6.0 without Service Pack 11
  • Sun Java System Web Server 6.1 without Service Pack 7
  • Sun Java System Web Server 6.1 without patch 121510-03

Windows Platform

  • Sun Java System Web Server 6.0 without Service Pack 11
  • Sun Java System Web Server 6.1 without Service Pack 7
  • Sun Java System Web Server 6.1 without patch 121524-03

Note: Sun Java System Web Server 7.0 is not affected by this issue.

To determine the version of Sun Java System Web Server on a system, the following command can be run:

    $ <WS-install>/https-<host>/start -version

 


Symptoms

There are no reliable symptoms that would indicate the described issue has occurred.


Workaround

There is no workaround.  Please see Resolution section below.


Resolution

This issue is addressed in the following releases:

SPARC Platform

  • Sun Java System Web Server 6.0 with Service Pack 11 or later
  • Sun Java System Web Server 6.1 with Service Pack 7 or later
  • Sun Java System Web Server 6.1 with patch 116648-19 or later

x86 Platform

  • Sun Java System Web Server 6.1 with Service Pack 7 or later
  • Sun Java System Web Server 6.1 with patch 116649-19 or later

Linux Platform

  • Sun Java System Web Server 6.0 with Service Pack 11 or later
  • Sun Java System Web Server 6.1 with Service Pack 7 or later
  • Sun Java System Web Server 6.1 with patch 118202-11 or later

AIX Platform

  • Sun Java System Web Server 6.0 with Service Pack 11 or later
  • Sun Java System Web Server 6.1 with Service Pack 7 or later

HP-UX Platform

  • Sun Java System Web Server 6.0 with Service Pack 11 or later
  • Sun Java System Web Server 6.1 with Service Pack 7 or later
  • Sun Java System Web Server 6.1 with patch 121510-03 or later

Windows Platform

  • Sun Java System Web Server 6.0 with Service Pack 11 or later
  • Sun Java System Web Server 6.1 with Service Pack 7 or later
  • Sun Java System Web Server 6.1 with patch 121524-03 or later

Sun Java System Web Server 6.0 Service Pack 11 is available at:

Sun Java System Web Server 6.1 Service Pack 7 is available at:






Attachments
This solution has no attachment

 
 
Login Required

You must login and have a valid contract to access Sun's Premium content which includes:

  • Sun Alerts
  • Bugs
  • Patches
  • Solutions
  • White Papers
  • Documentation
  • Support Knowledge

Login Required

You must login and have a valid contract to access Sun's contracted features

Access Legend:

(Login to access)   Sun Contracted Content
(Login to access)   Sun Contracted Feature

Please make use of SunSolve Feedback application by selecting the floating [+] to provide feedback about this specific document.

Search

Article Details
Article ID : 201545
Article Type : Sun Alert
Last reviewed : 2007-05-31
Audience : PUBLIC
Keywords :
Provide feedback  (help)
Page Tools
»  Print This Page
»  Email This Article
»  Bookmark This Article