Secunia Logo  


Secunia PSI WorldMap
 
Vulnerability Report: Sun Java System Web Server (Sun ONE/iPlanet) 6.x
This vulnerability report for Sun Java System Web Server (Sun ONE/iPlanet) 6.x contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.

If you have information about a new or an existing vulnerability in Sun Java System Web Server (Sun ONE/iPlanet) 6.x then you are more than welcome to contact us.


Table of Contents

1. Product Summary Only

2. Secunia Advisory Statistics (All time)
2.1. Statistics for 2009
2.2. Statistics for 2008
2.3. Statistics for 2007
2.4. Statistics for 2006
2.5. Statistics for 2005
2.6. Statistics for 2004
2.7. Statistics for 2003

3. List of Secunia Advisories (All time)
3.1. List for 2009
3.2. List for 2008
3.3. List for 2007
3.4. List for 2006
3.5. List for 2005
3.6. List for 2004
3.7. List for 2003

4. Send Feedback
 
Vendor, Links, and Unpatched Vulnerabilities

Vendor Sun Microsystems

Product Link View Here (Link to external site)

Affected By 27 Secunia advisories
18 Vulnerabilities

Monitor Product Receive alerts for this product

Unpatched 0% (0 of 27 Secunia advisories)

Most Critical Unpatched
There are no unpatched Secunia advisories affecting this product, when all vendor patches are applied..




27 Secunia Advisories in 2003-2009
Secunia has issued a total of 27 Secunia advisories in 2003-2009 for Sun Java System Web Server (Sun ONE/iPlanet) 6.x. Currently, 0% (0 out of 27) are marked as unpatched.

More information about the specific Secunia advisories affecting Sun Java System Web Server (Sun ONE/iPlanet) 6.x can be found below. Each Secunia advisory is enclosed by a box highlighted with a color representing its current patch status. You can read the complete Secunia advisories for thorough descriptions of the issues covered and for solution suggestions by clicking either the Secunia advisory title or the "Read More" links available for each Secunia advisory.



Sun Java System Web Server Java Server Pages Content Disclosure
Vendor Workaround. Secunia Advisory 1 of 2 in 2009. 1,685 views.
Release Date:
2009-07-06
Secunia Advisory ID:
SA35701
Solution Status:
Vendor Workaround
Criticality:
Impact:
Exposure of sensitive information
Where:
From remote
Short Description:
A vulnerability has been discovered in Sun Java System Web Server, which can be exploited by malicious people to gain knowledge of potentially sensitive information. [Read More]


Sun Java System Web Server Reverse Proxy Plug-in Cross-Site Scripting
Vendor Patch. Secunia Advisory 2 of 2 in 2009. 1,384 views.
Release Date:
2009-06-04
Secunia Advisory ID:
SA35338
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
A vulnerability has been reported in Sun Java System Web Server, which can be exploited by malicious people to conduct cross-site scripting attacks. [Read More]


Sun Java System Web Server Advanced Search Cross-Site Scripting
Vendor Patch. Secunia Advisory 1 of 3 in 2008. 5,599 views.
Release Date:
2008-05-26
Secunia Advisory ID:
SA30381
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
A vulnerability has been reported in Sun Java System Web Server, which can be exploited by malicious people to conduct cross-site scripting attacks. [Read More]


Sun Java System Web Server Search Module Cross-Site Scripting Vulnerability
Vendor Patch. Secunia Advisory 2 of 3 in 2008. 4,744 views.
Release Date:
2008-05-08
Secunia Advisory ID:
SA30133
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
Sun has acknowledged a vulnerability in Sun Java System Web Server, which can be exploited by malicious people to conduct cross-site scripting attacks. [Read More]


Sun Java System Web Server / Application Server JSP Information Disclosure
Vendor Patch. Secunia Advisory 3 of 3 in 2008. 6,359 views.
Release Date:
2008-05-08
Secunia Advisory ID:
SA30122
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
Where:
From remote
Short Description:
Sun has acknowledged a vulnerability in Sun Java System Web Server and Sun Java System Application Server, which can be exploited by malicious people to disclose certain sensitive information. [Read More]


Sun Java System Web Server / Web Proxy Server Cross-Site Scripting
Vendor Patch. Secunia Advisory 1 of 5 in 2007. 6,785 views.
Release Date:
2007-12-24
Secunia Advisory ID:
SA28216
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Sun Java System Web Server / Web Proxy Server, which can be exploited by malicious people to conduct cross-site scripting attacks. [Read More]


Sun Java System Web Server "redirect" Vulnerability
Vendor Patch. Secunia Advisory 2 of 5 in 2007. 10,787 views.
Release Date:
2007-08-03
Secunia Advisory ID:
SA26326
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Exposure of sensitive information
Where:
From remote
Short Description:
A vulnerability has been reported in Sun Java System Web Server, which can be exploited by malicious people to conduct HTTP header injection attacks, HTTP response splitting attacks, and disclose potentially sensitive information. [Read More]


Sun Java System Products NSS SSLv2 Processing Buffer Overflows
Partial Fix. Secunia Advisory 3 of 5 in 2007. 7,368 views.
Release Date:
2007-06-12
Secunia Advisory ID:
SA25597
Solution Status:
Partial Fix
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Sun has acknowledged some vulnerabilities in various Sun Java System products, which potentially can be exploited by malicious people to compromise a vulnerable system. [Read More]


Sun Java System Web Server Unspecified Information Disclosure
Vendor Patch. Secunia Advisory 4 of 5 in 2007. 8,389 views.
Release Date:
2007-03-16
Secunia Advisory ID:
SA24545
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
Where:
From remote
Short Description:
Sun has acknowledged a vulnerability in Sun Java System Web Server, which can be exploited by malicious users to disclose potentially sensitive information. [Read More]


Sun Java System Web Server Revoked Certificate Security Bypass
Vendor Patch. Secunia Advisory 5 of 5 in 2007. 9,870 views.
Release Date:
2007-03-15
Secunia Advisory ID:
SA24531
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
Sun has acknowledged a vulnerability in Sun Java System Web Server, which can be exploited by malicious users to bypass certain security restriction. [Read More]


Sun Java System Server Products HTTP Request Smuggling
Vendor Patch. Secunia Advisory 1 of 5 in 2006. 9,595 views.
Release Date:
2006-12-04
Secunia Advisory ID:
SA23186
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Cross Site Scripting
Manipulation of data
Where:
From remote
Short Description:
Sun has acknowledged a vulnerability in various Sun Java System Server products, which can be exploited by malicious people to conduct HTTP request smuggling attacks. [Read More]


Sun Java System Multiple Products RSA Signature Forgery
Vendor Patch. Secunia Advisory 2 of 5 in 2006. 9,548 views.
Release Date:
2006-11-06
Secunia Advisory ID:
SA22733
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
Sun has acknowledged a vulnerability in various Sun Java System products, which can be exploited by malicious people to bypass certain security restrictions. [Read More]


Sun ONE/Java System Web Server NSS Denial of Service
Vendor Patch. Secunia Advisory 3 of 5 in 2006. 8,459 views.
Release Date:
2006-11-01
Secunia Advisory ID:
SA22646
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
A vulnerability has been reported in Sun ONE Application Server and Sun Java System Web Server, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Sun Java System Application Server / Web Server File Disclosure
Vendor Patch. Secunia Advisory 4 of 5 in 2006. 11,772 views.
Release Date:
2006-07-28
Secunia Advisory ID:
SA21251
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of system information
Exposure of sensitive information
Where:
From remote
Short Description:
A vulnerability has been reported in Sun Java System Application Server (SJSAS) and Sun Java System Web Server (SJSWS), which can be exploited by malicious people to gain knowledge of sensitive information. [Read More]


Sun ONE/Java System Web Server Cross-Site Scripting
Vendor Patch. Secunia Advisory 5 of 5 in 2006. 11,309 views.
Release Date:
2006-05-19
Secunia Advisory ID:
SA20147
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
Keigo Yamazaki has reported a vulnerability in Sun ONE and Sun Java System Web Server, which can be exploited by malicious people to conduct cross-site scripting attacks. [Read More]


Sun Java System Web Server Unspecified Denial of Service
Vendor Patch. Secunia Advisory 1 of 1 in 2005. 8,296 views.
Release Date:
2005-04-14
Secunia Advisory ID:
SA14961
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
A vulnerability has been reported in Sun Java System Web Server, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Sun Java System Web Server / Application Server Session ID Disclosure
Vendor Patch. Secunia Advisory 1 of 6 in 2004. 9,218 views.
Release Date:
2004-12-14
Secunia Advisory ID:
SA13437
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
Where:
From remote
Short Description:
A vulnerability has been reported in Sun Java System Web Server and Application Server, which can be exploited by malicious people to gain knowledge of sensitive information. [Read More]


Sun Java System Web and Application Server Certificate Handling Denial of Service
Vendor Patch. Secunia Advisory 2 of 6 in 2004. 10,297 views.
Release Date:
2004-11-03
Secunia Advisory ID:
SA13072
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Sun Java System Web Server and Sun Java System Application Server, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Sun Java System Web Server NSS Library Vulnerability
Vendor Patch. Secunia Advisory 3 of 6 in 2004. 9,811 views.
Release Date:
2004-08-25
Secunia Advisory ID:
SA12378
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
ISS X-Force has reported a vulnerability in the NSS library included with Sun Java System Web Server, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Sun Java System Web Server Cross Site Scripting Vulnerability
Vendor Patch. Secunia Advisory 4 of 6 in 2004. 7,055 views.
Release Date:
2004-07-23
Secunia Advisory ID:
SA12135
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
Sun has issued an update for Sun Java System Web Server. This fixes a vulnerability, allowing malicious people to conduct Cross Site Scripting attacks. [Read More]


Sun Java System (Sun ONE) SSL Vulnerabilities
Vendor Patch. Secunia Advisory 5 of 6 in 2004. 11,681 views.
Release Date:
2004-03-10
Secunia Advisory ID:
SA11082
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
Sun has issued updated packages for Sun Java System Web Server and Application Server (formerly Sun ONE). These fix various vulnerabilities, which can be exploited by malicious people to cause a Denial of Service and potentially compromise a vulnerable system. [Read More]


Sun ONE Web Server Unspecified Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 6 of 6 in 2004. 11,139 views.
Release Date:
2004-01-12
Secunia Advisory ID:
SA10597
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Sun has reported a vulnerability in Sun ONE Web Server, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Sun ONE Web Server Unspecified Denial of Service Vulnerability
Vendor Patch. Secunia Advisory 1 of 5 in 2003. 8,008 views.
Release Date:
2003-12-03
Secunia Advisory ID:
SA10345
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Sun has reported an unspecified vulnerability in Sun ONE Web Server, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Sun ONE Web Server Log Entry Manipulation Vulnerability
Vendor Patch. Secunia Advisory 2 of 5 in 2003. 8,145 views.
Release Date:
2003-11-18
Secunia Advisory ID:
SA10237
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Spoofing
Where:
From remote
Short Description:
Sun has acknowledged a vulnerability in Sun One Web Server, which can be exploited by malicious people to manipulate log entries. [Read More]


Sun ONE Web Server Unspecified Denial of Service
Vendor Patch. Secunia Advisory 3 of 5 in 2003. 8,900 views.
Release Date:
2003-08-15
Secunia Advisory ID:
SA9541
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Sun has reported a vulnerability in Sun ONE Web Server, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Sun ONE Web Server and Application Server CBC Timing Attack Vulnerability
Vendor Workaround. Secunia Advisory 4 of 5 in 2003. 6,250 views.
Release Date:
2003-05-07
Secunia Advisory ID:
SA8741
Solution Status:
Vendor Workaround
Criticality:
Impact:
Exposure of sensitive information
Where:
From remote
Short Description:
Sun has confirmed a vulnerability in Sun ONE Web Server and Application Server, which can be exploited by malicious people to gain knowledge of a plaintext block used to encrypt an SSL/TLS session. [Read More]


Multiple products allow Cross Site Scripting and log spoofing
Partial Fix. Secunia Advisory 5 of 5 in 2003. 13,072 views.
Release Date:
2003-03-12
Secunia Advisory ID:
SA8275
Solution Status:
Partial Fix
Criticality:
Impact:
Security Bypass
Cross Site Scripting
Spoofing
Where:
From remote
Short Description:
Various techniques have been identified to use DNS to perform Cross Site Scripting and to spoof an IP address in web server log files and log analysers. [Read More]