Bugraq ID: 35217 CNCAN ID:CNCAN-2009060604 Sun GlassFish Enterprise Server是一款构建和部署下一代应用程序和服务的开源和开放社区平台。 Sun GlassFish Enterprise Server HTTP引擎和管理接口存在多个安全问题,远程和本地攻击者可以利用漏洞进行跨站脚本执行和拒绝服务等攻击。 -允许远程非特权用户在验证用户浏览器会话中执行JavaScript,导致泄漏敏感信息。 -允许本地特权用户消耗大量系统资源,造成拒绝服务攻击。 Sun Glassfish Enterprise Server 2.1 厂商解决方案 可参考如下补丁: Sun Glassfish Enterprise Server 2.1 Sun 128640-10 SPARC <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -128640-10-1 Sun 128641-10 x86 <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -128641-10-1 Sun 128642-10 Linux <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external...
Bugraq ID: 35217 CNCAN ID:CNCAN-2009060604 Sun GlassFish Enterprise Server是一款构建和部署下一代应用程序和服务的开源和开放社区平台。 Sun GlassFish Enterprise Server HTTP引擎和管理接口存在多个安全问题,远程和本地攻击者可以利用漏洞进行跨站脚本执行和拒绝服务等攻击。 -允许远程非特权用户在验证用户浏览器会话中执行JavaScript,导致泄漏敏感信息。 -允许本地特权用户消耗大量系统资源,造成拒绝服务攻击。 Sun Glassfish Enterprise Server 2.1 厂商解决方案 可参考如下补丁: Sun Glassfish Enterprise Server 2.1 Sun 128640-10 SPARC <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -128640-10-1 Sun 128641-10 x86 <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -128641-10-1 Sun 128642-10 Linux <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -128642-10-1 Sun 128643-10 SPARC <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -128643-10-1 Sun 128644-10 x86 <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -128644-10-1 Sun 128645-10 Linux <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -128645-10-1 Sun 128646-10 Windows <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -128646-10-1 Sun 128647-10 SPARC <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -128647-10-1 Sun 128648-10 x86 <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -128648-10-1 Sun 128649-10 Linux <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -128649-10-1 Sun 128650-10 Windows <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -128650-10-1 Sun 137916-09 AIX <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -137916-09-1 Sun 141700-01 SPARC <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -141700-01-1 Sun 141701-01 x86 <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -141701-01-1 Sun 141702-01 Linux <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -141702-01-1 Sun 141703-01 Windows <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -141703-01-1 Sun 141704-01 SPARC <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -141704-01-1 Sun 141705-01 x86 <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -141705-01-1 Sun 141706-01 Linux <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -141706-01-1 Sun 141707-01 Windows <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -141707-01-1 Sun 141708-01 AIX <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -141708-01-1 Sun 141709-01 SPARC <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -141709-01-1 Sun 141710-01 x86 <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -141710-01-1 Sun 141711-01 Linux <a href="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21" target="_blank" rel=external nofollow>http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21</a> -141711-01-1