CVE Vulnerabilities

CVE-2009-1594

Published: May 21, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the positive model, which allows remote attackers to bypass certain protection mechanisms via a %0A (encoded newline), as demonstrated by a %0A in a cross-site scripting (XSS) attack URL.

Affected Software

NameVendorStart VersionEnd Version
Profense_web_application_firewallArmorlogic*2.2.21 (including)
Profense_web_application_firewallArmorlogic2.4 (including)2.4 (including)

References