CVE-2010-0360: Input Validation
Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to overwrite memory locations in the heap, and discover the contents of memory locations, via a malformed HTTP TRACE request that includes a long URI and many empty headers, related to an "overflow." NOTE: this might overlap CVE-2010-0272 and CVE-2010-0273.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0360?
CVE-2010-0360 has been classified as having a medium severity level.
How do I fix CVE-2010-0360?
To fix CVE-2010-0360, upgrade Sun Java System Web Server to a version higher than 7.0 Update 7.
What kind of attack vectors are associated with CVE-2010-0360?
CVE-2010-0360 allows remote attackers to exploit a malformed HTTP TRACE request.
What are the potential impacts of CVE-2010-0360?
The potential impacts of CVE-2010-0360 include memory overwrites and exposure of sensitive information.
Is CVE-2010-0360 specific to any version of Sun Java System Web Server?
Yes, CVE-2010-0360 specifically affects Sun Java System Web Server 7.0 Update 7.