VulnerabilityModified
CVE-2000-0869
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.
MEDIUM 5.0EPSS 50.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 50.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 50.95% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- apache/http server · suse/suse linux
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/linux/suse/2000-q3/0906.htmlVendor Advisory
- http://www.atstake.com/research/advisories/2000/a090700-3.txtVendor Advisory
- http://www.securityfocus.com/bid/1656Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5204
- http://archives.neohapsis.com/archives/linux/suse/2000-q3/0906.htmlVendor Advisory
- http://www.atstake.com/research/advisories/2000/a090700-3.txtVendor Advisory
- http://www.securityfocus.com/bid/1656Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5204
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.