CVE-2009-3457
29.09.2009, 18:00
Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request, leading to a Message-handling Errors message containing a certain client intranet IP address, aka Bug ID CSCtb82159.Enginsight
Vendor | Product | Version |
---|---|---|
cisco | ace_web_application_firewall | 𝑥 ≤ 6.0\(3\) |
cisco | ace_web_application_firewall | 6.0\(0\) |
cisco | ace_web_application_firewall | 6.0\(1\) |
cisco | ace_web_application_firewall | 6.0\(2\) |
cisco | ace_xml_gateway | 𝑥 ≤ 6.0\(3\) |
cisco | ace_xml_gateway | 6.0\(0\) |
cisco | ace_xml_gateway | 6.0\(1\) |
cisco | ace_xml_gateway | 6.0\(2\) |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References