27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

within\nthe client browser.<br />

Solution: Upgrade to version 2.0.5 or higher.<br />

CVE-2005-0791<br />

IBM WebSphere 'ResetPassword' Information Disclosure<br />

<strong>PVS</strong> ID: 2712 FAMILY: Web Servers RISK: LOW NESSUS ID:17337<br />

Description: Synopsis :\n\nThe remote host may give an attacker information useful for future<br />

attacks.\n\nThe remote WebSphere webserver is vulnerable to an information leak. There is<br />

a flaw in the default ResetPassword form that would allow a remote attacker to obtain<br />

potentially confidential data (such as UserID) within the web server cache. An attacker<br />

exploiting this flaw would only need to be able to browse to the affected system and view<br />

the confidential data within the form source code.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE Not available<br />

Ximian Evolution < 2.0.4 Content-Parsing DoS<br />

<strong>PVS</strong> ID: 2713 FAMILY: SMTP Clients<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Denial of Service (DoS) attack.\n\nThe<br />

remote host is running a version of the Ximian Evolution email client that does not properly<br />

validate malformed Unicode messages. By processing a malformed message, the client will<br />

crash.<br />

Solution: Upgrade to version 2.0.4 or higher.<br />

CVE Not available<br />

Jetty < 4.2.19 HttpRequest.java Content-Length DoS<br />

<strong>PVS</strong> ID: 2714 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:17348<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Denial of Service (DoS) attack.\n\nThe<br />

remote host is running Jetty, a Java web server that can be downloaded off the Internet and<br />

is currently bundled with some IBM applications. This version of Jetty is vulnerable to a<br />

remote Denial of Service (DoS) attack. An attacker exploiting this flaw would be able to<br />

render the web server unavailable.<br />

Solution: Upgrade to version 4.2.19 or higher.<br />

CVE-2004-2381<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 697

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!