CVE-2006-6697: CRLF Injection
CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6697?
CVE-2006-6697 is considered a high severity vulnerability due to its potential for HTTP response splitting attacks.
How do I fix CVE-2006-6697?
To fix CVE-2006-6697, ensure that your Oracle Portal version is updated to a patched release that addresses this CRLF injection issue.
What systems are affected by CVE-2006-6697?
CVE-2006-6697 affects Oracle Portal versions 9.0.2 and 10g.
What type of attacks can be performed using CVE-2006-6697?
CVE-2006-6697 can be exploited to conduct HTTP response splitting attacks which can lead to session hijacking or cache poisoning.
Is CVE-2006-6697 exploitable remotely?
Yes, CVE-2006-6697 is exploitable by remote attackers who can send crafted requests to the vulnerable server.