PT-2005-2580 · Apache+1 · Apache Tomcat+1

Published

2005-05-16

·

Updated

2017-07-11

·

CVE-2005-1601

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions MRO Maximo Self Service versions 4 and 5
Description The issue allows remote attackers to obtain sensitive information by making a direct request for certain files, such as MXServer.properties, which are stored under the web document root using file extensions that are not processed by Tomcat.
Recommendations For versions 4 and 5, consider restricting access to sensitive files, such as MXServer.properties, to prevent unauthorized disclosure of information. As a temporary workaround, restrict access to the web document root to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1601

Affected Products

Mro Maximo Self Service
Apache Tomcat