PT-2009-3394 · Apache+2 · Apache Tomcat+2

Published

2009-06-03

·

Updated

2023-02-13

·

CVE-2009-0783

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 4.1.0 through 4.1.39 Apache Tomcat versions 5.5.0 through 5.5.27 Apache Tomcat versions 6.0.0 through 6.0.18
Description The issue allows local users to read or modify the web.xml, context.xml, or tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. This is possible because a web application can replace the XML parser used by Tomcat to process these files. In limited circumstances, a rogue web application may be able to view and/or alter the web.xml, context.xml, and tld files of other web applications deployed on the Tomcat instance.
Recommendations For Apache Tomcat versions 4.1.0 through 4.1.39, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 5.5.0 through 5.5.27, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 6.0.0 through 6.0.18, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the XML parser used by Tomcat to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2009-0783
DSA-2207-1
GHSA-HHJG-G8XQ-HHR3
HPSBUX02579
HPSBUX02860
RHSA-2009:1143
RHSA-2009:1144
RHSA-2009:1145
RHSA-2009:1146
RHSA-2009:1164
RHSA-2009:1454
RHSA-2009:1506
RHSA-2009:1562
RHSA-2009:1563
RHSA-2009:1616
RHSA-2009:1617
RHSA-2009_1164

Affected Products

Apache Tomcat
Hp-Ux
Red Hat