PT-2001-1788 · Apache · Apache Tomcat

Publicado

2001-08-02

·

Atualizado

2022-04-30

·

CVE-2001-0590

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Apache Software Foundation Tomcat Servlet versions prior to 3.2.2
Description: The issue allows a remote attacker to read the source code of arbitrary 'jsp' files via a specially crafted URL. This can be achieved by sending a malformed URL request that does not end with an HTTP protocol specification, such as HTTP/1.0. The estimated number of potentially affected devices and details about real-world incidents are not provided.
Recommendations: For versions prior to 3.2.2, update to version 3.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive JSP files until the update is applied.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2001-0590
GHSA-X445-MMPW-7R4F

Produtos afetados

Apache Tomcat