PT-2015-4004 · Apache+1 · Apache Tomcat Connectors+1

Published

2015-04-21

·

Updated

2024-06-15

·

CVE-2014-8111

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat Connectors (mod jk) versions prior to 1.2.41
Description The issue allows remote attackers to access restricted artifacts due to the ignoring of JkUnmount rules for subtrees of previous JkMount rules.
Recommendations For versions prior to 1.2.41, update to version 1.2.41 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8111
DLA-240-1
DSA-3278-1
MGASA-2015-0254
OPENSUSE-SU-2024:10488-1
RHSA-2015:0846
RHSA-2015:0847
RHSA-2015:0848
RHSA-2015:1642
SUSE-SU-2015:1851-1
SUSE-SU-2015_1851-1
SUSE-SU-2018:3970-1

Affected Products

Apache Tomcat Connectors
Suse