PT-2008-2825 · Apache+2 · Apache Tomcat+2

Published

2008-07-31

·

Updated

2023-02-13

·

CVE-2008-1232

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 4.1.0 through 4.1.37 Apache Tomcat versions 5.5.0 through 5.5.26 Apache Tomcat versions 6.0.0 through 6.0.16
Description The issue allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method. This may include characters that are illegal in HTTP headers, resulting in arbitrary content being injected into the HTTP response. For a successful attack, unfiltered user-supplied data must be included in the message argument.
Recommendations For Apache Tomcat versions 4.1.0 through 4.1.37, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 5.5.0 through 5.5.26, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 6.0.0 through 6.0.16, update to a version outside of this range to resolve the issue. As a temporary workaround, consider filtering user-supplied data used in the message argument to the sendError method to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2008-1232
GHSA-Q74X-QQHR-F8RX
HPSBUX02401
RHSA-2008:0648
RHSA-2008:0862
RHSA-2008:0864
RHSA-2008:0877
RHSA-2008:1007
RHSA-2008_0648
RHSA-2010:0602

Affected Products

Apache Tomcat
Hp-Ux
Red Hat