PT-2000-1691 · Apache · Jakarta Tomcat+1

Publicado

2000-10-20

·

Atualizado

2022-04-30

·

CVE-2000-0759

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jakarta Tomcat version 3.1
Description The issue allows a remote attacker to obtain physical path information when requesting a non-existent URL, resulting in an error message that includes the physical path. This occurs because requesting a non-existent JSP page generates an error page that includes the full file system path of the current context.
Recommendations For Jakarta Tomcat version 3.1, consider configuring the server to handle errors in a way that does not reveal sensitive path information, such as by creating a custom error page. As a temporary workaround, restrict access to non-existent URLs to minimize the risk of exploitation.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2000-0759
GHSA-QG4G-6JCQ-RW93

Produtos afetados

Apache Tomcat
Jakarta Tomcat