CVE Vulnerabilities

CVE-2007-4164

Published: Aug 07, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

CRLF injection vulnerability in the redirect feature in Sun Java System Web Server 6.1 and 7.0 before 20070802, when the redirect Server Application Function (SAF) uses the url-prefix parameter and escape is disabled, or an Error directive uses the url-prefix parameter in obj.conf, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks.

Affected Software

NameVendorStart VersionEnd Version
Java_system_web_serverSun6.1 (including)6.1 (including)
Java_system_web_serverSun6.1-sp1 (including)6.1-sp1 (including)
Java_system_web_serverSun6.1-sp2 (including)6.1-sp2 (including)
Java_system_web_serverSun6.1-sp3 (including)6.1-sp3 (including)
Java_system_web_serverSun6.1-sp4 (including)6.1-sp4 (including)
Java_system_web_serverSun6.1-sp5 (including)6.1-sp5 (including)
Java_system_web_serverSun6.1-sp6 (including)6.1-sp6 (including)
Java_system_web_serverSun6.1-sp7 (including)6.1-sp7 (including)
Java_system_web_serverSun7.0 (including)7.0 (including)

References