CVE-2003-0412
published 2003-06-30CVE-2003-0412: Sun ONE Application Server 7.0 for Windows 2000/XP does not log the complete URI of a long HTTP request, which could allow remote attackers to hide malicious…
PriorityP417medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.73%
75.0th percentile
Sun ONE Application Server 7.0 for Windows 2000/XP does not log the complete URI of a long HTTP request, which could allow remote attackers to hide malicious activities.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | one_application_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CWE
Information Loss or Omission
mitre_cwe·CVSS 7.5
[HIGH] CWE-221 Information Loss or Omission
CWE-221: Information Loss or Omission
The product does not record, or improperly records, security-relevant information that leads to an incorrect decision or hampers later analysis.
Modes of Introduction:
Phase: Architecture and Design
Phase: Implementation
Phase: Operation
Common Consequences:
Scope: Non-Repudiation. Impact: Hide Activities.
Examples:
This code logs suspicious multiple login attempts.
This code only logs failed login attempts when a certain limit is reached. If an attacker knows this limit, they can stop their attack from being discovered by avoiding the limit.
Observed Examples:
CVE-2004-2227: Web browser's filename selection dialog only shows the beginning portion of long filenames, which can trick users into launching executables with dangerous extensions.
CVE-20
CWE
Truncation of Security-relevant Information
mitre_cwe·CVSS 5.0
[MEDIUM] CWE-222 Truncation of Security-relevant Information
CWE-222: Truncation of Security-relevant Information
The product truncates the display, recording, or processing of security-relevant information in a way that can obscure the source or nature of an attack.
Modes of Introduction:
Phase: Implementation
Phase: Operation
Common Consequences:
Scope: Non-Repudiation. Impact: Hide Activities. The source of an attack will be difficult or impossible to determine. This can allow attacks to the system to continue without notice.
Observed Examples:
CVE-2005-0585: Web browser truncates long sub-domains or paths, facilitating phishing.
CVE-2004-2032: Bypass URL filter via a long URL with a large number of trailing hex-encoded space characters.
CVE-2003-0412: application server does not log complete URI of a long request (truncation).
http://marc.info/?l=bugtraq&m=105409846029475&w=2http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&zone_32=category%3Asecurityhttp://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1http://www.ciac.org/ciac/bulletins/n-103.shtmlhttp://www.securityfocus.com/bid/7711http://www.spidynamics.com/sunone_alert.htmlhttp://marc.info/?l=bugtraq&m=105409846029475&w=2http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&zone_32=category%3Asecurityhttp://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1http://www.ciac.org/ciac/bulletins/n-103.shtmlhttp://www.securityfocus.com/bid/7711http://www.spidynamics.com/sunone_alert.html
2003-06-30
Published