CVE-2010-0387

Sun Java System Web Server 7.0 Update 7 - Heap-Based Buffer Overflow via Long Digest Authorization Header

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-0387. PoCs published by Intevydis.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Sun Java System Web Server by sending a maliciously crafted HTTP PUT request with an overly long 'Authorization: Digest' header. The lack of boundary checks can lead to arbitrary code execution or denial-of-service.

Description

Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7 allow remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long string in an "Authorization: Digest" HTTP header.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Intevydis · textremotemultiple
https://www.exploit-db.com/exploits/33553

This exploit targets a buffer overflow vulnerability in Sun Java System Web Server by sending a maliciously crafted HTTP PUT request with an overly long 'Authorization: Digest' header. The lack of boundary checks can lead to arbitrary code execution or denial-of-service.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Sun Java System Web Server 7.0 without Update Release 8, Sun Java System Web Server 6.1 without Service Pack 12, Sun Java System Web Proxy Server 4.0 without Service pack 13
No auth needed
Prerequisites: Network access to the target server · Target server running vulnerable version of Sun Java System Web Server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/55792
Various Sources mailing-list x_refsource_mlist
http://lists.immunitysec.com/pipermail/dailydave/2010-January/006014.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1023488
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/37896

Scores

EPSS 0.0770
EPSS Percentile 93.8%

Details

CWE
CWE-119
Status published
Products (1)
sun/java_system_web_server 7.0 update_7
Published Jan 25, 2010
Tracked Since Feb 18, 2026