CVE-2006-3921

Sun Java System Application Server (SJSAS) 7 through 8.1 and Web Server (SJSWS) 6.0 and 6.1 allows remote authenticated users to read files outside of the "document root directory" via a direct request using a UTF-8 encoded URI.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sun:java_system_application_server:7.0:*:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:7.0:*:enterprise:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:7.0:*:platform:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:7.0:*:standard:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:7.0:ur1:enterprise:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:7.0:ur1:standard:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:7.0:ur2:enterprise:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:7.0:ur2:platform:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:7.0:ur2:standard:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:7.0:ur4:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:7.0:ur5:platform:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:7.0:ur5:standard:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:7.0:ur6:platform:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:7.0:ur6:standard:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:7.1:*:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.1:*:enterprise:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.1:*:platform:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.1:ur1:platform:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:6.0:*:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:6.1:*:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:6.1:sp1:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:6.1:sp2:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:6.1:sp3:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:6.1:sp4:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:6.1:sp5:*:*:*:*:*:*

History

21 Nov 2024, 00:14

Type Values Removed Values Added
References () http://secunia.com/advisories/21251 - () http://secunia.com/advisories/21251 -
References () http://secunia.com/advisories/22425 - () http://secunia.com/advisories/22425 -
References () http://securitytracker.com/id?1016596 - Patch () http://securitytracker.com/id?1016596 - Patch
References () http://securitytracker.com/id?1016597 - Patch () http://securitytracker.com/id?1016597 - Patch
References () http://sunsolve.sun.com/search/document.do?assetkey=1-26-102521-1 - Patch () http://sunsolve.sun.com/search/document.do?assetkey=1-26-102521-1 - Patch
References () http://support.avaya.com/elmodocs2/security/ASA-2006-204.htm - () http://support.avaya.com/elmodocs2/security/ASA-2006-204.htm -
References () http://www.securityfocus.com/bid/19200 - Patch () http://www.securityfocus.com/bid/19200 - Patch
References () http://www.vupen.com/english/advisories/2006/3020 - () http://www.vupen.com/english/advisories/2006/3020 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/28061 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/28061 -

Information

Published : 2006-07-28 23:04

Updated : 2024-11-21 00:14


NVD link : CVE-2006-3921

Mitre link : CVE-2006-3921

CVE.ORG link : CVE-2006-3921


JSON object : View

Products Affected

sun

  • java_system_web_server
  • java_system_application_server