First published: Mon Dec 04 2006(Updated: )
HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypass HTTP request filtering, hijack web sessions, perform cross-site scripting (XSS), and poison web caches via unspecified attack vectors.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun ONE Application Server | =7.0 | |
Sun Java System Web Server | =6.0-sp9 | |
Sun Java System Web Server | =6.1-sp1 | |
Sun Java System Web Proxy Server | =3.6-sp1 | |
Sun Java System Web Server | =6.0-sp1 | |
Sun ONE Application Server | =7.0-ur1 | |
Sun ONE Application Server | =7.0-ur1 | |
Sun Java System Web Proxy Server | =3.6-sp6 | |
Sun Java System Application Server | =7.0-ur1 | |
Sun Java System Application Server | =7.0-ur2 | |
Sun Java System Web Server | =6.0 | |
Sun Java System Application Server | =8.1 | |
Sun ONE Application Server | =7.0-ur2 | |
Sun Java System Web Proxy Server | =3.6-sp2 | |
Sun ONE Application Server | =7.0-ur6 | |
Sun Java System Web Server | =6.1-sp3 | |
Sun Java System Application Server | =7.0-ur3 | |
Sun Java System Application Server | =8.1 | |
Sun Java System Web Server | =6.0-sp4 | |
Sun Java System Web Server | =6.0-sp6 | |
Sun ONE Application Server | =7.0 | |
Sun Java System Web Proxy Server | =3.6-sp5 | |
Sun Java System Web Server | =6.0-sp2 | |
Sun ONE Application Server | =7.0-ur7 | |
Sun ONE Application Server | =7.0-update_3 | |
Sun Java System Web Server | =6.1 | |
Sun Java System Web Server | =6.0-sp7 | |
Sun Java System Web Server | =6.1-sp4 | |
Sun Java System Web Proxy Server | =3.6-sp7 | |
Sun Java System Application Server | =7.0-ur1 | |
Sun ONE Application Server | =7.0-ur2 | |
Sun Java System Application Server | =7.0-ur2 | |
Sun Java System Web Proxy Server | =4.0 | |
Sun ONE Application Server | =7.0-ur7 | |
Sun Java System Web Proxy Server | =3.6-sp4 | |
Sun Java System Web Proxy Server | =3.6-sp3 | |
Sun Java System Application Server | =8.1-ur1 | |
Sun ONE Application Server | =7.0-ur6 | |
Sun Java System Web Server | =6.0-sp8 | |
Sun Java System Web Server | =6.0-sp3 | |
Sun Java System Web Proxy Server | =3.6 | |
Sun Java System Application Server | =7.0-ur3 | |
Sun Java System Web Server | =6.0-sp5 | |
Sun Java System Web Server | =6.1-sp2 | |
Sun Java System Application Server | =8.1 | |
Sun Java System Application Server | =7.0 | |
Sun Java System Application Server | =8.1 | |
Sun Java System Web Proxy Server | ||
Sun ONE Application Server | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6276 is considered a critical vulnerability due to its potential for allowing remote attackers to bypass HTTP request filtering and perform unauthorized actions.
To fix CVE-2006-6276, upgrade to the latest version of Sun Java System Proxy Server, or apply the appropriate patches provided by Sun Microsystems.
CVE-2006-6276 affects several products including Sun Java System Proxy Server, Sun Java System Application Server, and Sun Java System Web Server.
Exploitation of CVE-2006-6276 can lead to HTTP request smuggling, session hijacking, and cross-site scripting (XSS) attacks.
If an immediate patch is not available, implementing strict input validation and monitoring HTTP traffic can serve as temporary mitigations against CVE-2006-6276.