CVE-2010-0360

SUN Java System Web Server - Improper Input Validation

Title source: rule

Description

Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to overwrite memory locations in the heap, and discover the contents of memory locations, via a malformed HTTP TRACE request that includes a long URI and many empty headers, related to an "overflow." NOTE: this might overlap CVE-2010-0272 and CVE-2010-0273.

Scores

EPSS 0.0080
EPSS Percentile 73.8%

Classification

CWE
CWE-20
Status draft

Affected Products (1)

sun/java_system_web_server

Timeline

Published Jan 20, 2010
Tracked Since Feb 18, 2026