THE CENZIC BLOG
Read more articles in  Cenzic SmartAttack Updates for Web Vulnerabilities
.
January 22, 2010

Cenzic Detects a Java System Web Server Remote Code Execution Vulnerability

Weekly product update – Cenzic detects a Java System Web Server Remote Code Execution Vulnerability

As of January 22, 2010 Cenzic now detects a Java System Web Server Remote Code Execution Vulnerability (BugtraqID 37641).  Sun Java System Web Server is prone to a remote code execution vulnerability.  Attackers can exploit this issue to execute code within the context of the affected application.  Sun Java System Web Server 7.0 Update 6 is vulnerable, however other versions may also be affected.

Background on Cenzic’s SmartAttacks
Every week, Cenzic’s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect "holes" in Web applications.  These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.

by
Erin Swanson
Eswanson@cenzic.com

Topic Tags:  ,

Syndication OptionsRSS (Rich Site Summary) Feed Atom Feed OPML (Outline Processor Language) Feed MYST-ML (MyST Markup Language) Content Feed MS-Office Smart Tag Subscription