Interstage HTTP Server: Security Vulnerability (CVE-2012-0053). November 26th, 2013


Notes on using this web page

1. Description

Interstage HTTP Server does not properly restrict header information in Bad Request (also known as 400) error documents. This vulnerability will allow remote attackers to obtain the values of HTTPOnly cookies.
This vulnerability corresponds to CVE-2012-0053.

Fujitsu provides security patches shown in 3. Please apply them as soon as possible.

2. Impact

A remote attacker could obtain the cookies of a user, if the user executes the malformed script provided by the remote attacker.

3. Affected systems and corresponding action

3-1. Affected systems:

GP7000F, PRIMEPOWER, PRIMERGY, GP5000, CELSIUS, AT-compatible machine, PRIMEQUEST, SPARC Enterprise

3-2. Affected products and required patch

Interstage Application Server
ProductsVersionTarget OSPackage namePatch ID.
Interstage Application Server Enterprise Edition for Windows [*a]V5.0Windows NT4.0/ Windows 2000 ServerF3FMihsNone*
Interstage Application Server Enterprise Edition for Windows [*a]V6.0Windows NT4.0/ Windows 2000 Server/ Windows Server 2003F3FMihsNone*
Interstage Application Server Enterprise Edition for Windows [*a]V7.0/ V7.0.1Windows 2000 Server/ Windows Server 2003F3FMihsNone*
Interstage Application Server Enterprise Edition for Windows [*a]8.0.0/ 8.0.1/ 8.0.2Windows 2000 Server/ Windows Server 2003F3FMihsNone*
Interstage Application Server Enterprise Edition for Windows [*b]V9.0.0/ V9.0.0AWindows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2F3FMihsT001001WP-09
Interstage Application Server Enterprise Edition for Windows [*b]V9.1.0/ V9.1.0BWindows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008F3FMihsT002174WP-06
Interstage Application Server Enterprise Edition for Windows [*b]V9.2.0Windows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2F3FMihsT004344WP-05
Interstage Application Server Enterprise Edition for Windows [*b]V10.0.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2F3FMihsT006036WP-02
Interstage Application Server Enterprise Edition for Windows [*b]V11.0.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2/ Windows Small Business Server 2011/ Windows Server 2012F3FMihsT008632WP-01
Interstage Application Server Standard Edition for Windows [*a]V5.0Windows NT4.0/ Windows 2000 ServerF3FMihsNone*
Interstage Application Server Standard-J Edition for Windows [*a]8.0.0/ 8.0.1/ 8.0.2Windows 2000 Server/ Windows Server 2003F3FMihsNone*
Interstage Application Server Standard-J Edition for Windows [*b]V9.0.0/ V9.0.0A/ V9.0.0BWindows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2F3FMihsT001001WP-09
Interstage Application Server Standard-J Edition for Windows [*b]V9.1.0/ V9.1.0BWindows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008F3FMihsT002174WP-06
Interstage Application Server Standard-J Edition for Windows [*b]V9.2.0Windows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2F3FMihsT004344WP-05
Interstage Application Server Standard-J Edition for Windows [*b]V10.0.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2F3FMihsT006036WP-02
Interstage Application Server Standard-J Edition for Windows [*b]V11.0.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2/ Windows Small Business Server 2011/ Windows Server 2012F3FMihsT008632WP-01
Interstage Application Server Web-J Edition for Windows [*a]V5.0Windows NT4.0/ Windows 2000 ServerF3FMihsNone*
Interstage Application Server Plus for Windows [*a]V5.0.1Windows NT4.0/ Windows 2000 ServerF3FMihsNone*
Interstage Application Server Plus for Windows [*a]V6.0Windows NT4.0/ Windows 2000 Server/ Windows Server 2003F3FMihsNone*
Interstage Application Server Plus for Windows [*a]V7.0/ V7.0.1Windows 2000 Server/ Windows Server 2003F3FMihsNone*
Interstage Application Server Plus Developer for Windows [*a]V5.0.1Windows NT4.0/ Windows 2000 Server/ Windows XPF3FMihsNone*
Interstage Application Server Plus Developer for Windows [*a]V6.0Windows NT4.0/ Windows 2000 Server/ Windows XP/ Windows Server 2003F3FMihsNone*
Interstage Application Server Plus Developer for Windows [*a]V7.0Windows 2000 Server/ Windows XP/ Windows Server 2003F3FMihsNone*
Interstage Application Server Enterprise Edition for Windows [*a]8.0.0Windows(IPF) Server 2003F3FMihsNone*
Interstage Application Server Enterprise Edition for Windows [*b]V9.0.0Windows(IPF) Server 2003/ Windows(IPF) Server 2003 R2F3FMihsT001005IP-07
Interstage Application Server Enterprise Edition for Windows [*b]V9.1.0Windows(IPF) Server 2003/ Windows(IPF) Server 2003 R2/ Windows(IPF) Server 2008F3FMihsT002175IP-06
Interstage Application Server Enterprise Edition for Windows [*b]V9.2.0Windows(IPF) Server 2003/ Windows(IPF) Server 2003 R2/ Windows(IPF) Server 2008F3FMihsT004345IP-05
Interstage Application Server Standard-J Edition for Windows [*b]V9.0.0Windows(IPF) Server 2003/ Windows(IPF) Server 2003 R2F3FMihsT001005IP-07
Interstage Application Server Standard-J Edition for Windows [*b]V9.1.0Windows(IPF) Server 2003/ Windows(IPF) Server 2003 R2/ Windows(IPF) Server 2008F3FMihsT002175IP-06
Interstage Application Server Standard-J Edition for Windows [*b]V9.2.0Windows(IPF) Server 2003/ Windows(IPF) Server 2003 R2/ Windows(IPF) Server 2008F3FMihsT004345IP-05
Interstage Application Server Enterprise Edition for Windows [*b]V9.2.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows(EM64T) Server 2008 R2F3FMihsT004346XP-05
Interstage Application Server Enterprise Edition for Windows [*b]V10.0.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows(EM64T) Server 2008 R2F3FMihsT006037XP-02
Interstage Application Server Enterprise Edition for Windows [*b]V11.0.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows(EM64T) Server 2008 R2/ Windows(EM64T) Small Business Server 2011/ Windows(EM64T) Server 2012F3FMihsT008633XP-01
Interstage Application Server Standard-J Edition for Windows [*b]V9.2.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows(EM64T) Server 2008 R2F3FMihsT004346XP-05
Interstage Application Server Standard-J Edition for Windows [*b]V10.0.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows(EM64T) Server 2008 R2F3FMihsT006037XP-02
Interstage Application Server Standard-J Edition for Windows [*b]V11.0.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows(EM64T) Server 2008 R2/ Windows(EM64T) Small Business Server 2011/ Windows(EM64T) Server 2012F3FMihsT008633XP-01
Interstage Application Server Enterprise Edition [*a]5.0Solaris 7/ 8/ 9FJSVihsNone*
Interstage Application Server Enterprise Edition [*a]5.0.1Solaris 7/ 8/ 9FJSVihsNone*
Interstage Application Server Enterprise Edition [*a]6.0Solaris 7/ 8/ 9FJSVihsNone*
Interstage Application Server Enterprise Edition [*a]7.0Solaris 8/ 9FJSVihsNone*
Interstage Application Server Enterprise Edition [*a]7.0.1Solaris 8/ 9/ 10FJSVihsNone*
Interstage Application Server Enterprise Edition [*a]8.0.0/ 8.0.2Solaris 9/ 10FJSVihsNone*
Interstage Application Server Enterprise Edition [*b]V9.0.0/ V9.0.0BSolaris 9/ 10FJSVihsT001004SP-09
Interstage Application Server Enterprise Edition [*b]V9.1.0/ V9.1.0BSolaris 9/ 10FJSVihsT002180SP-07
Interstage Application Server Enterprise Edition [*b]V9.2.0Solaris 9/ 10FJSVihsT004343SP-05
Interstage Application Server Enterprise Edition [*b]V10.0.0Solaris 9/ 10FJSVihsT006035SP-02
Interstage Application Server Enterprise Edition [*b]V11.0.0Solaris 10/ 11FJSVihsT008627SP-01
Interstage Application Server Standard Edition [*a]5.0Solaris 7/ 8/ 9FJSVihsNone*
Interstage Application Server Standard-J Edition [*a]8.0.0/ 8.0.2Solaris 9/ 10FJSVihsNone*
Interstage Application Server Standard-J Edition [*b]V9.0.0Solaris 9/ 10FJSVihsT001004SP-09
Interstage Application Server Standard-J Edition [*b]V9.1.0/ V9.1.0BSolaris 9/ 10FJSVihsT002180SP-07
Interstage Application Server Standard-J Edition [*b]V9.2.0Solaris 9/ 10FJSVihsT004343SP-05
Interstage Application Server Standard-J Edition [*b]V10.0.0Solaris 9/ 10FJSVihsT006035SP-02
Interstage Application Server Standard-J Edition [*b]V11.0.0Solaris 10/ 11FJSVihsT008627SP-01
Interstage Application Server Web-J Edition [*a]5.0Solaris 7/ 8/ 9FJSVihsNone*
Interstage Application Server Plus [*a]7.0Solaris 8/ 9FJSVihsNone*
Interstage Application Server Plus [*a]7.0.1Solaris 8/ 9/ 10FJSVihsNone*
Interstage Application Server Enterprise Edition for Linux [*a]V5.0Turbolinux 7 ServerFJSVihsNone*
Interstage Application Server Standard Edition for Linux [*a]V5.0Turbolinux 7 ServerFJSVihsNone*
Interstage Application Server Web-J Edition for Linux [*a]V5.0Turbolinux 7 ServerFJSVihsNone*
Interstage Application Server Enterprise Edition for Linux [*a]V6.0RHEL-AS3(x86)/ ES3(x86)FJSVihsNone*
Interstage Application Server Enterprise Edition for Linux [*a]V7.0RHEL-AS3(x86)/ ES3(x86)FJSVihsNone*
Interstage Application Server Plus for Linux [*a]V7.0RHEL-AS3(x86)/ ES3(x86)FJSVihsNone*
Interstage Application Server Enterprise Edition for Linux [*a]V7.0.1RHEL-AS3(x86)/ ES3(x86)/ AS4(x86)FJSVihsNone*
Interstage Application Server Plus for Linux [*a]V7.0.1RHEL-AS3(x86)/ ES3(x86)/ AS4(x86)FJSVihsNone*
Interstage Application Server Enterprise Edition for Linux [*a]8.0.0/ 8.0.2RHEL-AS4(x86)/ AS4(EM64T)FJSVihsNone*
Interstage Application Server Enterprise Edition for Linux [*b]V9.0.0RHEL-AS4(x86)/ AS4(EM64T)FJSVihsT001003LP-07
Interstage Application Server Enterprise Edition for Linux [*b]V9.1.0/ V9.1.0BRHEL-AS4(x86)/ AS4(EM64T)FJSVihsT002176LP-06
Interstage Application Server Enterprise Edition for Linux [*b]V9.2.0/ V9.3.1RHEL-AS4(x86)/ AS4(EM64T)FJSVihsT004338LP-05
Interstage Application Server Standard-J Edition for Linux [*a]8.0.0/ 8.0.2RHEL-AS4(x86)/ AS4(EM64T)FJSVihsNone*
Interstage Application Server Standard-J Edition for Linux [*b]V9.0.0RHEL-AS4(x86)/ AS4(EM64T)FJSVihsT001003LP-07
Interstage Application Server Standard-J Edition for Linux [*b]V9.1.0/ V9.1.0BRHEL-AS4(x86)/ AS4(EM64T)FJSVihsT002176LP-06
Interstage Application Server Standard-J Edition for Linux [*b]V9.2.0/ V9.3.1RHEL-AS4(x86)/ AS4(EM64T)FJSVihsT004338LP-05
Interstage Application Server Enterprise Edition for Linux [*b]V9.0.0RHEL5(x86)/ RHEL5(Intel64)FJSVihsT001044LP-07
Interstage Application Server Enterprise Edition for Linux [*b]V9.1.0/ V9.1.0BRHEL5(x86)/ RHEL5(Intel64)FJSVihsT002177LP-06
Interstage Application Server Enterprise Edition for Linux [*b]V9.2.0/ V9.3.1RHEL5(x86)/ RHEL5(Intel64)FJSVihsT004339LP-05
Interstage Application Server Enterprise Edition for Linux [*b]V10.0.0RHEL5(x86)/ RHEL5(Intel64)FJSVihsT006038LP-02
Interstage Application Server Enterprise Edition for Linux [*b]V11.0.0RHEL5(x86)/ RHEL5(Intel64)FJSVihsT008628LP-01
Interstage Application Server Standard-J Edition for Linux [*b]V9.0.0RHEL5(x86)/ RHEL5(Intel64)FJSVihsT001044LP-07
Interstage Application Server Standard-J Edition for Linux [*b]V9.1.0/ V9.1.0BRHEL5(x86)/ RHEL5(Intel64)FJSVihsT002177LP-06
Interstage Application Server Standard-J Edition for Linux [*b]V9.2.0/ V9.3.1RHEL5(x86)/ RHEL5(Intel64)FJSVihsT004339LP-05
Interstage Application Server Standard-J Edition for Linux [*b]V10.0.0RHEL5(x86)/ RHEL5(Intel64)FJSVihsT006038LP-02
Interstage Application Server Standard-J Edition for Linux [*b]V11.0.0RHEL5(x86)/ RHEL5(Intel64)FJSVihsT008628LP-01
Interstage Application Server Enterprise Edition for Linux [*b]V9.3.1RHEL6(x86)/ RHEL6(Intel64)FJSVihsT006033LP-02
Interstage Application Server Enterprise Edition for Linux [*b]V10.0.0RHEL6(x86)/ RHEL6(Intel64)FJSVihsT006039LP-02
Interstage Application Server Enterprise Edition for Linux [*b]V11.0.0RHEL6(x86)/ RHEL6(Intel64)FJSVihsT008629LP-01
Interstage Application Server Standard-J Edition for Linux [*b]V9.3.1RHEL6(x86)/ RHEL6(Intel64)FJSVihsT006033LP-02
Interstage Application Server Standard-J Edition for Linux [*b]V10.0.0RHEL6(x86)/ RHEL6(Intel64)FJSVihsT006039LP-02
Interstage Application Server Standard-J Edition for Linux [*b]V11.0.0RHEL6(x86)/ RHEL6(Intel64)FJSVihsT008629LP-01
Interstage Application Server Enterprise Edition for Linux [*a]V7.0RHEL-AS4(IPF)FJSVihsNone*
Interstage Application Server Enterprise Edition for Linux [*a]8.0.0/ 8.0.1/ 8.0.2RHEL-AS4(IPF)FJSVihsNone*
Interstage Application Server Enterprise Edition for Linux [*b]V9.0.0/ V9.0.0ARHEL-AS4(IPF)FJSVihsT001002QP-08
Interstage Application Server Enterprise Edition for Linux [*b]V9.1.0RHEL-AS4(IPF)FJSVihsT002178QP-06
Interstage Application Server Enterprise Edition for Linux [*b]V9.2.0RHEL-AS4(IPF)FJSVihsT004340QP-05
Interstage Application Server Standard-J Edition for Linux [*b]V9.0.0RHEL-AS4(IPF)FJSVihsT001002QP-08
Interstage Application Server Standard-J Edition for Linux [*b]V9.1.0RHEL-AS4(IPF)FJSVihsT002178QP-06
Interstage Application Server Standard-J Edition for Linux [*b]V9.2.0RHEL-AS4(IPF)FJSVihsT004340QP-05
Interstage Application Server Enterprise Edition for Linux [*b]V9.0.0/ V9.0.0ARHEL5(IPF)FJSVihsT001043QP-08
Interstage Application Server Enterprise Edition for Linux [*b]V9.1.0RHEL5(IPF)FJSVihsT002179QP-06
Interstage Application Server Enterprise Edition for Linux [*b]V9.2.0RHEL5(IPF)FJSVihsT004341QP-05
Interstage Application Server Standard-J Edition for Linux [*b]V9.0.0RHEL5(IPF)FJSVihsT001043QP-08
Interstage Application Server Standard-J Edition for Linux [*b]V9.1.0RHEL5(IPF)FJSVihsT002179QP-06
Interstage Application Server Standard-J Edition for Linux [*b]V9.2.0RHEL5(IPF)FJSVihsT004341QP-05
Interstage Application Server Enterprise Edition for Linux [*b]V9.2.0/ V9.3.1RHEL5(Intel64)FJSVihsT004342LP-05
Interstage Application Server Enterprise Edition for Linux [*b]V10.0.0RHEL5(Intel64)FJSVihsT006040LP-02
Interstage Application Server Enterprise Edition for Linux [*b]V11.0.0RHEL5(Intel64)FJSVihsT008630LP-01
Interstage Application Server Standard-J Edition for Linux [*b]V9.2.0/ V9.3.1RHEL5(Intel64)FJSVihsT004342LP-05
Interstage Application Server Standard-J Edition for Linux [*b]V10.0.0RHEL5(Intel64)FJSVihsT006040LP-02
Interstage Application Server Standard-J Edition for Linux [*b]V11.0.0RHEL5(Intel64)FJSVihsT008630LP-01
Interstage Application Server Enterprise Edition for Linux [*b]V9.3.1RHEL6(Intel64)FJSVihsT006034LP-02
Interstage Application Server Enterprise Edition for Linux [*b]V10.0.0RHEL6(Intel64)FJSVihsT006041LP-02
Interstage Application Server Enterprise Edition for Linux [*b]V11.0.0RHEL6(Intel64)FJSVihsT008631LP-01
Interstage Application Server Standard-J Edition for Linux [*b]V9.3.1RHEL6(Intel64)FJSVihsT006034LP-02
Interstage Application Server Standard-J Edition for Linux [*b]V10.0.0RHEL6(Intel64)FJSVihsT006041LP-02
Interstage Application Server Standard-J Edition for Linux [*b]V11.0.0RHEL6(Intel64)FJSVihsT008631LP-01
Interstage Apworks
ProductsVersionTarget OSPackage namePatch ID.
Interstage Apworks Modelers-J Edition for Windows [*a]V6.0/ V6.0AWindows 2000 Server/ Windows XPF3FMihsNone*
Interstage Apworks Modelers-J Edition for Windows [*a]V7.0Windows 2000 Server/ Windows XPF3FMihsNone*
Interstage Studio
ProductsVersionTarget OSPackage namePatch ID.
Interstage Studio Enterprise Edition for Windows [*a]8.0.1Windows 2000 Server/ Windows XP/ Windows Server 2003F3FMihsNone*
Interstage Studio Enterprise Edition for Windows [*b]V9.0.0Windows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows XP/ Windows VistaF3FMihsT001001WP-09
Interstage Studio Enterprise Edition for Windows [*b]V9.1.0/ V9.1.0BWindows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows XP/ Windows VistaF3FMihsT002174WP-06
Interstage Studio Enterprise Edition for Windows [*b]V9.2.0Windows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2/ Windows XP/ Windows Vista/ Windows 7F3FMihsT004344WP-05
Interstage Studio Standard-J Edition for Windows [*a]8.0.1Windows 2000 Server/ Windows XP/ Windows Server 2003F3FMihsNone*
Interstage Studio Standard-J Edition for Windows [*b]V9.0.0Windows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows XP/ Windows VistaF3FMihsT001001WP-09
Interstage Studio Standard-J Edition for Windows [*b]V9.1.0/ V9.1.0BWindows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows XP/ Windows VistaF3FMihsT002174WP-06
Interstage Studio Standard-J Edition for Windows [*b]V9.2.0Windows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2/ Windows XP/ Windows Vista/ Windows 7F3FMihsT004344WP-05
Interstage Studio Standard-J Edition for Windows [*b]V10.0.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2/ Windows XP/ Windows Vista/ Windows 7F3FMihsT006036WP-02
Interstage Studio Standard-J Edition for Windows [*b]V11.0.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2/ Windows XP/ Windows Vista/ Windows 7/ Windows Small Business Server 2011/ Windows Server 2012/ Windows 8F3FMihsT008632WP-01
Interstage Business Application Server
ProductsVersionTarget OSPackage namePatch ID.
Interstage Business Application Server Enterprise Edition for Linux [*a]8.0.0RHEL-AS4(IPF)FJSVihsNone*
Interstage Job Workload Server
ProductsVersionTarget OSPackage namePatch ID.
Interstage Job Workload Server for Linux [*a]8.1.0RHEL-AS4(IPF)FJSVihsNone*

For the solution, please refer to the following "3-3. Workaround".
The "3-3 Workaround" depends on the product. Refer to the letter in the square brackets at the end of the product name for details.

Note: Determining the affected product
To check the software version, refer to the "FUJITSU SOFTWARE RELEASE GUIDE" supplied with the product.

3-3. Workaround

Avoid the problem by editing the environment definition file (httpd.conf) with the following method and setting the error message of the status code 400 to a text message. After editing the file, Interstage HTTP Server must be restarted.

  • For [*a] products:
    Specify the text message after double quotation marks (").
        Specification example: ErrorDocument 400 "400 Bad Request
  • For [*b] products:
    Enclose the text message in double quotation marks (").
        Specification example: ErrorDocument 400 "400 Bad Request"

4. Related information

  • CVE-2012-0053
    protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0053

5. Revision history

  • November 26th, 2013: 2nd release
    • Change the Patch ID in "3-2. Affected products and required patch".
    • Add some products to "3-2. Affected products and required patch".
  • October 9th, 2012: Initial release

Top of Page