CVE-1999-1478: Medium severity Microsoft Internet Information Server vulnerability
The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure IIS Request Filtering (or URLScan) to reject any HTTP requests whose URL contains the '[' character.
Microsoft Internet Information Services request filtering - block '[' in URL = deny - Compensating control
At the network edge (WAF, reverse proxy or firewall), drop or sanitize HTTP requests that contain the '[' character in the requested URL to prevent the triggering of the HotSpot-related DoS.
- Operational
Enable logging and alerting for HTTP requests that include the '[' character; investigate and isolate hosts showing suspicious volume of such requests and perform incident response as needed.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1478?
CVE-1999-1478 is classified as a denial of service vulnerability that can significantly affect server availability.
How do I fix CVE-1999-1478?
To address CVE-1999-1478, it is recommended to update the Microsoft Internet Information Server to a version that is not susceptible to this vulnerability.
Which software is affected by CVE-1999-1478?
CVE-1999-1478 specifically affects Microsoft Internet Information Server versions 3.0 and 4.0.
Can CVE-1999-1478 be exploited remotely?
Yes, CVE-1999-1478 can be exploited by remote attackers via specially crafted URLs.
What impact does CVE-1999-1478 have on servers?
The impact of CVE-1999-1478 is that it can lead to a denial of service, making the affected servers unresponsive.