MEDIUM · 4.3

CVE-2005-3398

The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the HTTP TRACE method, which could allow remote attackers to obtain sensitive infor...

Vulnerability Description

The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the HTTP TRACE method, which could allow remote attackers to obtain sensitive information such as cookies and authentication data from HTTP headers.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
SunSolaris9.0
SunSunos5.8

Related Weaknesses (CWE)

References

FAQ

What is CVE-2005-3398?

CVE-2005-3398 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the HTTP TRACE method, which could allow remote attackers to obtain sensitive infor...

How severe is CVE-2005-3398?

CVE-2005-3398 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-3398?

Check the references section above for vendor advisories and patch information. Affected products include: Sun Solaris, Sun Sunos.