PT-2009-1291 · Apache+2 · Apache Tomcat+2

Published

2009-06-03

·

Updated

2023-02-13

·

CVE-2008-5515

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 4.1.0 through 4.1.39 Apache Tomcat versions 5.5.0 through 5.5.27 Apache Tomcat versions 6.0.0 through 6.0.18
Description The issue allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request. This is due to the normalization of the target pathname before filtering the query string when using the RequestDispatcher method. A request that includes a specially crafted request parameter could be used to access content that would otherwise be protected by a security constraint or by locating it under the WEB-INF directory.
Recommendations For Apache Tomcat versions 4.1.0 through 4.1.39, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 5.5.0 through 5.5.27, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 6.0.0 through 6.0.18, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the WEB-INF directory to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2008-5515
DSA-2207-1
GHSA-9737-QMGC-HFR9
HPSBUX02579
HPSBUX02860
RHSA-2009:1143
RHSA-2009:1144
RHSA-2009:1145
RHSA-2009:1146
RHSA-2009:1164
RHSA-2009:1454
RHSA-2009:1506
RHSA-2009:1562
RHSA-2009:1563
RHSA-2009:1616
RHSA-2009:1617
RHSA-2009_1164
RHSA-2010:0602

Affected Products

Apache Tomcat
Hp-Ux
Red Hat