Vulnerability CVE-2009-1191


Published: 2009-04-23   Modified: 2013-04-17

Description:
mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.

Type:

CWE-20

(Improper Input Validation)

Vendor: Apache
Product: Apache http server 
Version: 2.2.11;

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None

 References:
http://www.securityfocus.com/bid/34663
http://www.apache.org/dist/httpd/patches/apply_to_2.2.11/PR46949.diff
http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=766938&r2=767089
https://issues.apache.org/bugzilla/show_bug.cgi?id=46949
http://xforce.iss.net/xforce/xfdb/50059
http://www.vupen.com/english/advisories/2009/3184
http://www.vupen.com/english/advisories/2009/1147
http://www.ubuntu.com/usn/usn-787-1
http://www.securitytracker.com/id?1022264
http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html
http://www.mandriva.com/security/advisories?name=MDVSA-2009:102
http://support.apple.com/kb/HT3937
http://security.gentoo.org/glsa/glsa-200907-04.xml
http://secunia.com/advisories/35721
http://secunia.com/advisories/35395
http://secunia.com/advisories/34827
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8261
http://osvdb.org/53921
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html

Related CVE
CVE-2015-3254
The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function.
CVE-2017-7676
Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended behavior.
CVE-2017-7677
In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for create table.
CVE-2016-8751
Apache Ranger before 0.6.is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies.
CVE-2016-8746
Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true.
CVE-2017-7667
Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin.
CVE-2017-7665
In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.
CVE-2015-5175
Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service.

Copyright 2017, cxsecurity.com