CVE Vulnerabilities

CVE-2009-1594

Published: May 21, 2009 | Modified: Oct 10, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the positive model, which allows remote attackers to bypass certain protection mechanisms via a %0A (encoded newline), as demonstrated by a %0A in a cross-site scripting (XSS) attack URL.

Affected Software

Name Vendor Start Version End Version
Profense_web_application_firewall Armorlogic * 2.2.21 (including)
Profense_web_application_firewall Armorlogic 2.4 (including) 2.4 (including)

References