vendor:
ServletExec
by:
SecurityFocus
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: ServletExec
Affected Version From: Unify eWave ServletExec
Affected Version To: Unify eWave ServletExec
Patch Exists: No
Related CWE: CVE-2001-0753
CPE: a:unify_corporation:servletexec
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft IIS, Apache, Netscape Enterprise Server
2001
Unify eWave ServletExec Denial of Service Vulnerability
Unify eWave ServletExec is vulnerable to a denial of service attack if a URL invoking the ServletExec servlet preceded by /servlet is requested. The ServletExec engine will attempt to bind a server thread over port 80 and if the web server is currently running, a java.net.BindException error will result thus halting all operations on the ServletExec engine.
Mitigation:
Restarting the application is required in order to regain normal functionality.