First published: Wed Apr 01 2009(Updated: )
Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allows remote attackers to cause a denial of service (daemon crash) via multiple requests to the default URI with alphabetic characters in the tzid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Communications Calendar Server | =6.0 | |
Oracle Communications Calendar Server | =6 | |
Oracle Communications Calendar Server | =6.3 | |
Oracle Communications Calendar Server | =6.3 | |
Oracle Communications Calendar Server | =6.0 | |
Oracle Communications Calendar Server | =6 | |
Oracle Communications Calendar Server | =6.3 | |
Oracle Communications Calendar Server | =6 | |
Oracle Communications Calendar Server | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1219 is classified as a denial of service vulnerability that can crash the Sun Calendar Express Web Server.
To fix CVE-2009-1219, update your Sun Calendar Server to a patched version that resolves the vulnerability.
CVE-2009-1219 affects Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server versions 6.0, 6, and 6.3.
Yes, CVE-2009-1219 can be exploited remotely by sending multiple requests to the default URI with specific parameters.
The impact of CVE-2009-1219 is a denial of service, resulting in the crashing of the server, which affects availability.