PT-2013-5085 · Apache+3 · Apache Tomcat+3

Vincent Danen

·

Published

2013-12-26

·

Updated

2022-05-14

·

CVE-2013-4590

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions prior to 6.0.39 Apache Tomcat versions 7.x prior to 7.0.50 Apache Tomcat versions 8.x prior to 8.0.0-RC10
Description The issue allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with certain XML documents containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. This occurs when Tomcat is running web applications from untrusted sources, such as in a shared hosting environment. The vulnerability can be exploited through XML files like web.xml, context.xml, *.tld, *.tagx, and *.jspx.
Recommendations For versions prior to 6.0.39, update to version 6.0.39 or later. For versions 7.x prior to 7.0.50, update to version 7.0.50 or later. For versions 8.x prior to 8.0.0-RC10, update to version 8.0.0-RC10 or later. As a temporary workaround, consider restricting access to untrusted web applications and limiting the use of XML files that may contain external entity declarations.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2014_1038
CVE-2013-4590
DLA-91-1
DSA-3530-1
GHSA-87W9-X2C3-HRJJ
MGASA-2014-0148
MGASA-2014-0149
RHSA-2014:1038
RHSA-2014:1087
RHSA-2014:1088
RHSA-2014_1038

Affected Products

Apache Tomcat
Centos
Red Hat
Vmware Vcenter