PT-2011-1433 · Apache+2 · Apache Tomcat+2
Published
2011-01-13
·
Updated
2023-02-13
·
CVE-2010-3718
CVSS v2.0
1.2
Low
| Vector | AV:L/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 7.0.0 through 7.0.3
Apache Tomcat version 6.0.x
Apache Tomcat version 5.5.x
Description
The issue allows local web applications to read or write files outside of the intended working directory when running within a SecurityManager. This is due to the ServletContext attribute not being made read-only, which can be exploited using a directory traversal attack. When running under a SecurityManager, access to the file system is limited, but web applications are granted read/write permissions to the work directory. A malicious web application may modify the ServletContext attribute to grant read/write permissions to any area on the file system.
Recommendations
For Apache Tomcat versions 7.0.0 through 7.0.3, consider restricting access to the work directory to minimize the risk of exploitation.
For Apache Tomcat version 6.0.x, restrict access to the work directory to prevent malicious web applications from modifying the ServletContext attribute.
For Apache Tomcat version 5.5.x, limit the permissions granted to web applications to prevent them from accessing unauthorized areas of the file system.
As a temporary workaround, consider disabling the writing of files to the work directory until a patch is available.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Tomcat
Hp-Ux
Red Hat