> Source: [sk111793](https://support.checkpoint.com/results/sk/sk111793)

# sk111793 - Security scan of Check Point software reports it as vulnerable to CVE-2009-4086

| Property | Value |
|----------|-------|
| Solution ID | sk111793 |
| Date Created | 2016-06-03 |
| Last Modified | 2016-06-05 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20, R82.x, R82.20 |

## Symptoms

- Security scan of Check Point Security Gateway reports it as vulnerable to [CVE-2009-4086](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4086).

## Cause

[CVE-2009-4086](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4086) states the following:

"CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via certain byte sequences at the end of a URL. NOTE: some of these details are obtained from third party information."

## Solution

Check Point software does *not* use the Xerver HTTP Server. Therefore, this is a false positive report.

Check Point provides IPS protection against this CVE:  
[Xerver HTTP CRLF Injection Response Splitting (CVE-2009-4086)](https://www.checkpoint.com/defense/advisories/public/2011/cpai-2011-318.html)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
