CVE-2006-6699: CRLF Injection
Multiple CRLF injection vulnerabilities in Oracle Portal 9.0.2 and possibly other versions allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter to (1) calendarDialog.jsp or (2) fred.jsp. NOTE: the calendar.jsp vector is covered by CVE-2006-6697.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6699?
CVE-2006-6699 is considered a high severity vulnerability due to its potential for HTTP response splitting attacks.
How do I fix CVE-2006-6699?
To fix CVE-2006-6699, upgrade Oracle Portal to a version that is not affected by this vulnerability.
What applications are affected by CVE-2006-6699?
CVE-2006-6699 affects Oracle Portal version 9.0.2 and possibly other versions.
What type of attack can be executed using CVE-2006-6699?
CVE-2006-6699 allows remote attackers to conduct HTTP response splitting attacks through CRLF injection.
What is the cause of the CVE-2006-6699 vulnerability?
The cause of CVE-2006-6699 is multiple CRLF injection vulnerabilities in the affected versions of Oracle Portal.