KLA11106
Multiple vulnerabilities in Apache Tomcat
Обновлено: 26/06/2019
Дата обнаружения
19/09/2017
Уровень угрозы
High
Описание

Multiple serious vulnerabilities have been found in Apache Tomcat. Malicious users can exploit these vulnerabilities to execute arbitrary code, bypass security restrictions and obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A vulnerability related to VirtualDirContext can be exploited remotely via specially designed request possibly to bypass security restrictions and/or obtain sensitive information;
  2. An unspecified vulnerability can be exploited remotely via specially designed request possibly to execute arbitrary code.

Technical details

Vulnerability (2) affects Windows systems with HTTP PUTs enabled only.

NB: This vulnerability does not have any public CVSS rating, so rating can be changed by the time.

Пораженные продукты

Apache Tomcat, versions from 7.0.0 to 7.0.80

Решение

Update to the latest version
Upgrade to Apache Tomcat 7.0.81

Первичный источник обнаружения
Apache Tomcat 7.x Security Vulnerabilities
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

SB 
[?]
Связанные продукты
Apache Tomcat
CVE-IDS