PT-2010-1267 · Apache+2 · Apache Tomcat+2

Publicado

2010-01-21

·

Atualizado

2022-05-02

·

CVE-2009-2693

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 5.5.0 through 5.5.28 Apache Tomcat versions 6.0.0 through 6.0.20
Description The issue allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file. This can be demonstrated by including entries such as ../../bin/catalina.bat or ../../bin/catalina.sh in the WAR file, enabling an attacker to create arbitrary content outside of the web root.
Recommendations For Apache Tomcat versions 5.5.0 through 5.5.28, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 6.0.0 through 6.0.20, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting the deployment of WAR files to trusted sources and validating the contents of WAR files for directory traversal attempts before deployment.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2693
DSA-2207-1
GHSA-GGX9-4728-588R
HPSBUX02541
HPSBUX02860
RHSA-2010:0119
RHSA-2010:0580
RHSA-2010:0582
RHSA-2010:0693
RHSA-2010_0580

Produtos afetados

Apache Tomcat
Hp-Ux
Red Hat