CVE-2009-3457

Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request, leading to a Message-handling Errors message containing a certain client intranet IP address, aka Bug ID CSCtb82159.
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:cisco:ace_web_application_firewall:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ace_web_application_firewall:6.0\(0\):*:*:*:*:*:*:*
cpe:2.3:h:cisco:ace_web_application_firewall:6.0\(1\):*:*:*:*:*:*:*
cpe:2.3:h:cisco:ace_web_application_firewall:6.0\(2\):*:*:*:*:*:*:*
cpe:2.3:h:cisco:ace_xml_gateway:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ace_xml_gateway:6.0\(0\):*:*:*:*:*:*:*
cpe:2.3:h:cisco:ace_xml_gateway:6.0\(1\):*:*:*:*:*:*:*
cpe:2.3:h:cisco:ace_xml_gateway:6.0\(2\):*:*:*:*:*:*:*

History

21 Nov 2024, 01:07

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2009/Sep/0369.html - Exploit, Patch () http://seclists.org/fulldisclosure/2009/Sep/0369.html - Exploit, Patch
References () http://secunia.com/advisories/36879 - () http://secunia.com/advisories/36879 -
References () http://www.brainoverflow.org/advisories/cisco_ace_xml_gw_ip_disclosure.txt - Exploit () http://www.brainoverflow.org/advisories/cisco_ace_xml_gw_ip_disclosure.txt - Exploit
References () http://www.cisco.com/en/US/products/products_security_response09186a0080af8965.html - () http://www.cisco.com/en/US/products/products_security_response09186a0080af8965.html -
References () http://www.securityfocus.com/archive/1/506716/100/0/threaded - () http://www.securityfocus.com/archive/1/506716/100/0/threaded -
References () http://www.securityfocus.com/bid/36522 - () http://www.securityfocus.com/bid/36522 -
References () http://www.securitytracker.com/id?1022949 - () http://www.securitytracker.com/id?1022949 -
References () http://www.vupen.com/english/advisories/2009/2778 - () http://www.vupen.com/english/advisories/2009/2778 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/53482 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/53482 -

Information

Published : 2009-09-29 18:00

Updated : 2024-11-21 01:07


NVD link : CVE-2009-3457

Mitre link : CVE-2009-3457

CVE.ORG link : CVE-2009-3457


JSON object : View

Products Affected

cisco

  • ace_xml_gateway
  • ace_web_application_firewall
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor