First published: Tue Sep 29 2009(Updated: )
Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request, leading to a Message-handling Errors message containing a certain client intranet IP address, aka Bug ID CSCtb82159.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Ace Xml Gateway | =6.0\(2\) | |
Cisco Ace Xml Gateway | =6.0\(0\) | |
Cisco Ace Xml Gateway | =6.0\(1\) | |
Cisco Ace Web Application Firewall | =6.0\(2\) | |
Cisco Ace Web Application Firewall | =6.0\(1\) | |
Cisco Ace Xml Gateway | <=6.0\(3\) | |
Cisco Ace Web Application Firewall | =6.0\(0\) | |
Cisco Ace Web Application Firewall | <=6.0\(3\) | |
Cisco ACE XML Gateway | <=6.0\(3\) | |
Cisco ACE XML Gateway | =6.0\(0\) | |
Cisco ACE XML Gateway | =6.0\(1\) | |
Cisco ACE XML Gateway | =6.0\(2\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.