First published: Thu May 24 2001(Updated: )
Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Java System Application Server | =4.0.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0419 is considered a critical vulnerability due to its potential to allow remote attackers to execute arbitrary commands.
To fix CVE-2001-0419, it is recommended to update the iPlanet Web Server to a patched version that addresses the buffer overflow issue.
CVE-2001-0419 affects the iPlanet Web Server 4.1 when used as a web listener for Oracle Application Server version 4.0.8.2.
CVE-2001-0419 enables remote command execution attacks by allowing attackers to send specially crafted HTTP requests.
While CVE-2001-0419 was disclosed many years ago, systems running the vulnerable software without patches remain at risk.