PT-2021-21718 · Unknown · Ttiny Java Web Server/Servlet Container
Maurizio Ruchay
·
Published
2021-08-09
·
Updated
2021-08-17
·
CVE-2021-37573
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TTiny Java Web Server and Servlet Container (TJWS) versions <=1.115
Description
A reflected cross-site scripting (XSS) issue allows an adversary to inject malicious code on the server's "404 Page not Found" error page. This occurs in the web server TTiny Java Web Server and Servlet Container (TJWS).
Recommendations
For versions <=1.115, update to a version greater than 1.115 to resolve the issue. As a temporary workaround, consider restricting access to the "404 Page not Found" error page until a patch is available.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ttiny Java Web Server/Servlet Container