CVE-2001-0746
Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with (1) GETPROPERTIES, (2)…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with (1) GETPROPERTIES, (2) GETATTRIBUTENAMES, or other methods.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 15.20% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- iplanet/iplanet web server
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2001-05/0132.htmlPatch, Vendor Advisory
- http://iplanet.com/products/iplanet_web_enterprise/iwsalert5.11.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/2732Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6554
- http://archives.neohapsis.com/archives/bugtraq/2001-05/0132.htmlPatch, Vendor Advisory
- http://iplanet.com/products/iplanet_web_enterprise/iwsalert5.11.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/2732Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6554
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.