Apache.httpOnly.Cookie.Disclosure

description-logoDescription

This indicates an attack attempt against a HTTP Cookies Disclosure vulnerability in Apache HTTP web server.
The vulnerability is caused because the vulnerable software does not properly restrict header information during construction of Bad Request error documents. It allows a remote attacker to obtain HTTP cookies via sending a crafted web script.

affected-products-logoAffected Products

Apache HTTP Server 2.2.x through 2.2.21

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Upgrade to the latest version, available from the web site.
http://httpd.apache.org/

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)