MEDIUM · 5.0

CVE-2009-3457

Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an...

Vulnerability Description

Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request, leading to a Message-handling Errors message containing a certain client intranet IP address, aka Bug ID CSCtb82159.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
CiscoAce Web Application Firewall<= 6.0\(3\)
CiscoAce Xml Gateway<= 6.0\(3\)

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-3457?

CVE-2009-3457 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an...

How severe is CVE-2009-3457?

CVE-2009-3457 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-3457?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ace Web Application Firewall, Cisco Ace Xml Gateway.