SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-6276

HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypass HTTP request filtering, hijack web sessions, perform…

MEDIUM 6.8EPSS 3.64%

Does this matter?

Lower severity and a low EPSS score (3.64%). Track it; it rarely justifies an emergency change on its own.

Description

HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypass HTTP request filtering, hijack web sessions, perform cross-site scripting (XSS), and poison web caches via unspecified attack vectors.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
3.64% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-444
Affected
sun/java system application server · sun/java system web proxy server · sun/java system web server · sun/one application server
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.