PT-2000-1692 · Apache · Jakarta Tomcat+1

Publicado

2000-10-20

·

Atualizado

2008-09-05

·

CVE-2000-0760

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jakarta Tomcat versions 3.0 through 3.1
Description The issue concerns the Snoop servlet in Jakarta Tomcat, which reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension. This occurs because the snoop servlet includes output that identifies the Tomcat installation path.
Recommendations For Jakarta Tomcat versions 3.0 through 3.1, consider disabling the Snoop servlet as a temporary workaround to minimize the risk of exploitation, as there are no plans to issue an update for this issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2000-0760

Produtos afetados

Apache Tomcat
Jakarta Tomcat