First published: Mon Jan 25 2010(Updated: )
The admin server in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP request that lacks a method token.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java System Web Server | =7.0-update_6 | |
Sun Java System Web Server | =7.0-update_7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0389 has a severity rating that indicates a denial of service vulnerability in the admin server of Sun Java System Web Server 7.0 Update 6.
To fix CVE-2010-0389, upgrade to a version of Sun Java System Web Server later than 7.0 Update 7 that addresses this vulnerability.
CVE-2010-0389 affects Sun Java System Web Server 7.0 Update 6 and Update 7.
CVE-2010-0389 is classified as a denial of service vulnerability due to a NULL pointer dereference leading to a daemon crash.
Yes, CVE-2010-0389 can be exploited remotely via specially crafted HTTP requests.