First published: Wed Oct 18 2000(Updated: )
The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java System Web Server | =1.1_beta | |
Sun Java System Web Server | =1.1.3 | |
Sun Java System Web Server | =2.0 | |
Sun Java System Web Server | =1.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0812 is classified as a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2000-0812, upgrade your Sun Java System Web Server to a version that is not affected, such as 2.0 or later.
CVE-2000-0812 can be exploited by remote attackers who upload malicious Java code via the administration module.
Versions 1.1_beta, 1.1.2, 1.1.3, and 2.0 of Sun Java System Web Server are vulnerable to CVE-2000-0812.
There is no specific patch for CVE-2000-0812; users must upgrade to a newer, unaffected version of the software.