CVE-2005-3398
The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the HTTP TRACE method, which could allow remote attackers to obtain sensitive information such as cookies and authentication data from…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the HTTP TRACE method, which could allow remote attackers to obtain sensitive information such as cookies and authentication data from HTTP headers.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 13.11% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- sun/solaris · sun/sunos
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/17334
- http://securitytracker.com/id?1015112Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102016-1Patch, Vendor Advisory
- http://www.securityfocus.com/bid/15222
- http://www.vupen.com/english/advisories/2005/2226
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1445
- http://secunia.com/advisories/17334
- http://securitytracker.com/id?1015112Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102016-1Patch, Vendor Advisory
- http://www.securityfocus.com/bid/15222
- http://www.vupen.com/english/advisories/2005/2226
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1445
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.