CVE-1999-1530: Low severity Sun Cobalt Raq 2 vulnerability
cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Sun Cobalt RaQ/cgiwrapfrom your environment.Disable or uninstall the cgiwrap component on affected Cobalt RaQ 2.0 and RaQ 3i systems until a vendor-supplied fix is available. Do not use cgiwrap to execute site scripts while the issue remains.
- Compensating control
Avoid co-hosting sites administered by different/untrusted administrators on the same RaQ system. Restrict site administrator privileges and isolate untrusted sites onto separate systems or virtual machines to prevent cross-site data access or modification.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1530?
CVE-1999-1530 is considered a critical vulnerability as it allows unauthorized access to sensitive data across virtual sites.
How do I fix CVE-1999-1530?
To fix CVE-1999-1530, update to a patched version of Cobalt RaQ where this vulnerability is addressed.
What systems are affected by CVE-1999-1530?
CVE-1999-1530 affects Sun Cobalt RaQ 2.0 and RaQ 3i systems.
What type of attack does CVE-1999-1530 enable?
CVE-1999-1530 enables a site administrator to view or modify data from other virtual sites on the same system.
Is CVE-1999-1530 still relevant in today's security landscape?
Yes, CVE-1999-1530 remains relevant as it highlights the risks associated with insecure user identification methods in web applications.