PT-2007-3208 · Apache+1 · Apache Tomcat Jk Web Server Connector+1

Published

2007-05-25

·

Updated

2023-02-13

·

CVE-2007-1860

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Apache Tomcat JK Web Server Connector versions 1.2.x through 1.2.22
Description: The issue allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal.
Recommendations: For Apache Tomcat JK Web Server Connector versions 1.2.x through 1.2.22, update to version 1.2.23 or later to resolve the issue.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2007-1860
DSA-1312-1
HPSBUX02262
RHSA-2007:0379
RHSA-2007:0380
RHSA-2008:0261
RHSA-2008:0524

Affected Products

Apache Tomcat Jk Web Server Connector
Hp-Ux