PT-2007-6497 · Apache+1 · Apache Tomcat+1

Published

2007-10-15

·

Updated

2022-05-01

·

CVE-2007-5461

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Apache Tomcat versions 4.0.0 through 4.0.6 Apache Tomcat version 4.1.0 Apache Tomcat versions 5.0.0 through 5.5.25 Apache Tomcat versions 6.0.0 through 6.0.14
Description: The issue allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag, under certain configurations. This occurs when Tomcat's WebDAV servlet is configured for use with a context and has been enabled for write. Some WebDAV requests can result in the contents of arbitrary files being returned to the client.
Recommendations: For Apache Tomcat versions 4.0.0 through 4.0.6, consider disabling the WebDAV servlet until a patch is available. For Apache Tomcat version 4.1.0, restrict access to the WebDAV servlet to minimize the risk of exploitation. For Apache Tomcat versions 5.0.0 through 5.5.25, avoid using the WebDAV write request with a SYSTEM tag until the issue is resolved. For Apache Tomcat versions 6.0.0 through 6.0.14, consider temporarily disabling the WebDAV servlet to prevent arbitrary file reads.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5461
DSA-1447-1
DSA-1453-1
GHSA-V5P2-VG3C-PMRR
RHSA-2008:0042
RHSA-2008:0151
RHSA-2008:0158
RHSA-2008:0195
RHSA-2008:0213
RHSA-2008:0261
RHSA-2008:0524
RHSA-2008:0630
RHSA-2008:0862
RHSA-2008_0042
RHSA-2010:0602

Affected Products

Apache Tomcat
Red Hat