HTTP: Apache HTTPD Error Code 400 httpOnly Cookie Handling Information Disclosure

This signature detects attempts to exploit a known vulnerability against Apache httpd. A successful attack can lead to unauthorized information disclosure and loss of sensitive information.

Extended Description

Apache HTTP Server is prone to an information-disclosure vulnerability. The issue occurs in the default error response for status code 400. Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks. The vulnerability affects Apache HTTP Server versions 2.2.0 through 2.2.21.

Affected Products

Avaya aura_messaging

References

BugTraq: 51706

CVE: CVE-2012-0053

Short Name
HTTP:APACHE:HTTPD-ERROR-400
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
400 Apache CVE-2012-0053 Code Cookie Disclosure Error HTTPD Handling Information bid:51706 httpOnly
Release Date
01/24/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Apache_software_foundation

Red_hat

Suse

Gentoo

Hp

Avaya

Mandriva

Slackware

Ubuntu

Oracle

Debian

CVSS Score

4.3

Found a potential security threat?