The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398. Per: http://sunsolve.sun.com/search/document.do?assetkey1-66-200942-1
Contributing Factors
This issue can occur in the following releases:
* Sun Java System Application Server Standard Edition 7 and later updates
* Sun Java System Application Server Standard Edition 7 2004Q2 and later updates
* Sun Java System Application Server Platform Edition 7 and later updates
Publication date: Tue, 26 Jan 2010 01:30:00 +0000