CVE-1999-0686: Medium severity Netscape Enterprise Server vulnerability
Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure NES (or the hosting web server settings) to enforce a maximum URL/request length and reject requests that exceed that limit to prevent long-URL induced DoS.
Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) maximum URL/request length = reject or drop requests that exceed the expected URL length for the application - Compensating control
Deploy perimeter filtering (WAF, reverse proxy, or firewall) to block or drop HTTP requests with excessively long URLs or malformed request lines before they reach the NES instance.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0686?
CVE-1999-0686 is classified as a denial of service vulnerability, which can disrupt service availability.
How does the CVE-1999-0686 vulnerability occur?
CVE-1999-0686 occurs when Netscape Enterprise Server fails to handle overly long URLs, leading to a crash.
Which systems are affected by CVE-1999-0686?
CVE-1999-0686 affects Netscape Enterprise Server running on HP-UX 10.24.
How do I fix CVE-1999-0686?
To remediate CVE-1999-0686, you should apply patches or updates provided by the vendor for Netscape Enterprise Server.
What is the impact of exploiting CVE-1999-0686?
Exploiting CVE-1999-0686 can lead to server downtime, affecting the availability of hosted services.