Overview
Apache Tomcat contains a vulnerability that may allow directory traversal.
Description
Apache Tomcat is an implementation of the Java Servlet and JavaServer Page (JSP) technologies. Apache Tomcat contains a vulnerability in the way malformed requests are handled. According to the Apache Tomcat 6.x Vulnerabilities page: If a context is configured with allowLinking="true" and the connector is configured with URIEncoding="UTF-8" then a malformed request may be used to access arbitrary files on the server. This vulnerability affects versions 4.1.0-4.1.37, 5.5.0-5.5.26, and 6.0.0-6.0.16. Note that we are aware of publicly-available exploit code for this vulnerability. |
Impact
A remote attacker could gain access to arbitrary files on the server. |
Solution
Apply an update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This issue was reported by William A. Rowe of Apache.
This document was written by Chris Taschner.
Other Information
CVE IDs: | CVE-2008-2938 |
Severity Metric: | 7.14 |
Date Public: | 2008-08-11 |
Date First Published: | 2008-08-19 |
Date Last Updated: | 2008-08-19 20:29 UTC |
Document Revision: | 5 |