vendor:
Sun Java System Web Server
by:
7.5
CVSS
HIGH
Format String Vulnerability
CWE
Product Name: Sun Java System Web Server
Affected Version From: Sun Java System Web Server 7.0 without Update Release 8
Affected Version To: Sun Java System Web Server 6.1 without Service Pack 12
Patch Exists:
Related CWE:
CPE:
Platforms Tested:
Format String Vulnerability in Sun Java System Web Server
Sun Java System Web Server is prone to a format-string vulnerability because it fails to properly sanitize user-supplied input. The issue affects the WebDAV functionality. Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.