CVE-2004-2763: Medium severity iplanet web server vulnerability
The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2763?
CVE-2004-2763 has a medium severity rating due to the potential for cross-site tracing attacks.
How do I fix CVE-2004-2763?
To fix CVE-2004-2763, disable HTTP TRACE requests on affected versions of the Sun ONE/iPlanet Web Server.
Which versions are affected by CVE-2004-2763?
CVE-2004-2763 affects Sun ONE Web Server versions 4.1 SP1 through SP12 and 6.0 SP1 through SP5, as well as Sun iPlanet Web Server versions 4.1 SP1 through SP12.
What kind of attacks does CVE-2004-2763 enable?
CVE-2004-2763 enables cross-site scripting (XSS) attacks through cross-site tracing (XST).
Is there a workaround for CVE-2004-2763?
A workaround for CVE-2004-2763 includes configuring the server to reject or not respond to TRACE requests.