PT-2024-21351 · Apache · Apache Tomcat

Jesús Antón

+1

·

Published

2024-03-19

·

Updated

2024-03-19

·

CVE-2024-2632

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Meta4 HR (affected versions not specified)
Description A vulnerability has been found that allows an attacker to obtain information about the application, including variables set in the process, Tomcat versions, library versions, and the underlying operating system. This is achieved via the HTTP GET endpoint "/sitetest/english/dumpenv.jsp".
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-2632

Affected Products

Apache Tomcat