PT-2011-1433 · Apache+2 · Apache Tomcat+2

Published

2011-01-13

·

Updated

2023-02-13

·

CVE-2010-3718

CVSS v2.0

1.2

Low

VectorAV:L/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 7.0.0 through 7.0.3 Apache Tomcat version 6.0.x Apache Tomcat version 5.5.x
Description The issue allows local web applications to read or write files outside of the intended working directory when running within a SecurityManager. This is due to the ServletContext attribute not being made read-only, which can be exploited using a directory traversal attack. When running under a SecurityManager, access to the file system is limited, but web applications are granted read/write permissions to the work directory. A malicious web application may modify the ServletContext attribute to grant read/write permissions to any area on the file system.
Recommendations For Apache Tomcat versions 7.0.0 through 7.0.3, consider restricting access to the work directory to minimize the risk of exploitation. For Apache Tomcat version 6.0.x, restrict access to the work directory to prevent malicious web applications from modifying the ServletContext attribute. For Apache Tomcat version 5.5.x, limit the permissions granted to web applications to prevent them from accessing unauthorized areas of the file system. As a temporary workaround, consider disabling the writing of files to the work directory until a patch is available.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2010-3718
DSA-2160-1
GHSA-FJ6C-PRGJ-GR3R
HPSBUX02645
HPSBUX02725
HPSBUX02860
RHSA-2011:0791
RHSA-2011:0897
RHSA-2011:1845
RHSA-2011_0791
RHSA-2011_1845

Affected Products

Apache Tomcat
Hp-Ux
Red Hat