PT-2007-1918 · Apache+2 · Apache Tomcat+3

Published

2007-02-28

·

Updated

2023-02-13

·

CVE-2007-0450

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server and Tomcat versions prior to 5.5.22 and 6.0.10 Tomcat versions prior to 5.5.22 and 6.0.10
Description The issue allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL. This occurs when using certain proxy modules, including mod proxy, mod rewrite, and mod jk. The characters are valid separators in Tomcat but not in Apache.
Recommendations For Apache HTTP Server and Tomcat versions prior to 5.5.22 and 6.0.10, consider disabling the mod proxy, mod rewrite, and mod jk modules until a patch is available. For Tomcat versions prior to 5.5.22 and 6.0.10, restrict access to the vulnerable proxy modules to minimize the risk of exploitation. Avoid using the .. (dot dot) sequence with combinations of / (slash), `` (backslash), and URL-encoded backslash (%5C) characters in the URL until the issue is resolved.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2007-0450
GHSA-4PRH-GQW8-RGH5
HPSBUX02262
RHSA-2007:0326
RHSA-2007:0327
RHSA-2007:0328
RHSA-2007:0340
RHSA-2007:0360
RHSA-2007:1069
RHSA-2007_0327
RHSA-2008:0261
RHSA-2008:0524
RHSA-2010:0602

Affected Products

Apache Http Server
Apache Tomcat
Hp-Ux
Red Hat