PT-2001-1788 · Apache · Apache Tomcat
Publicado
2001-08-02
·
Atualizado
2022-04-30
·
CVE-2001-0590
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache Software Foundation Tomcat Servlet versions prior to 3.2.2
Description:
The issue allows a remote attacker to read the source code of arbitrary 'jsp' files via a specially crafted URL. This can be achieved by sending a malformed URL request that does not end with an HTTP protocol specification, such as HTTP/1.0. The estimated number of potentially affected devices and details about real-world incidents are not provided.
Recommendations:
For versions prior to 3.2.2, update to version 3.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive JSP files until the update is applied.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Tomcat