|
Apache Tomcat Directory Traversal Security Issue
|
|
Secunia Advisory:
|
SA24732
|
|
|
Release Date:
|
2007-04-02
|
|
Popularity:
|
11,512 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Security Bypass
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Apache Tomcat 5.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2007-0450
|
|
Description: D. Matscheko has reported a security issue in Apache Tomcat, which can be exploited by malicious people to bypass certain security restrictions.
If Tomcat is running behind a proxy with context restriction, an error within the handling of certain path delimiters in requests ('2F', '%5C', and '\') can be exploited to bypass the context restrictions and may allow access to non-proxied contexts.
The security issue is reported in versions 5.5.0 to 5.5.21, 5.0.0 to 5.5.0.30, and 6.0.0 to 6.0.9.
Solution: Update to version 5.5.22 or 6.0.10.
Configure Apache Tomcat so that you don't have to rely on context restricting proxies.
Provided and/or discovered by: D. Matscheko
Original Advisory: http://www.sec-consult.com/287.html
http://tomcat.apache.org/security-5.html
http://tomcat.apache.org/security-6.html
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|