|
|
| |
| Apache Tomcat is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input. |
| |
Credit:
The original article can be found at: http://www.securityfocus.com/bid/37944
The information has been provided by Marc Schoenefeld.
|
| |
Vulnerable Systems:
* Apache Software Foundation Tomcat 6.0.20
* Apache Software Foundation Tomcat 6.0.18
* Apache Software Foundation Tomcat 6.0.16
* Apache Software Foundation Tomcat 6.0.15
* Apache Software Foundation Tomcat 6.0.14
* Apache Software Foundation Tomcat 6.0.13
* Apache Software Foundation Tomcat 6.0.12
* Apache Software Foundation Tomcat 6.0.11
* Apache Software Foundation Tomcat 6.0.10
* Apache Software Foundation Tomcat 6.0.9
* Apache Software Foundation Tomcat 6.0.8
* Apache Software Foundation Tomcat 6.0.7
* Apache Software Foundation Tomcat 6.0.6
* Apache Software Foundation Tomcat 6.0.5
* Apache Software Foundation Tomcat 6.0.4
* Apache Software Foundation Tomcat 6.0.3
* Apache Software Foundation Tomcat 6.0.2
* Apache Software Foundation Tomcat 6.0.1
* Apache Software Foundation Tomcat 6.0
* Apache Software Foundation Tomcat 5.5.28
* Apache Software Foundation Tomcat 5.5.27
* Apache Software Foundation Tomcat 5.5.26
* Apache Software Foundation Tomcat 5.5.25
* Apache Software Foundation Tomcat 5.5.24
* Apache Software Foundation Tomcat 5.5.23
* Apache Software Foundation Tomcat 5.5.22
* Apache Software Foundation Tomcat 5.5.21
* Apache Software Foundation Tomcat 5.5.20
* Apache Software Foundation Tomcat 5.5.19
* Apache Software Foundation Tomcat 5.5.18
* Apache Software Foundation Tomcat 5.5.17
* Apache Software Foundation Tomcat 5.5.16
* Apache Software Foundation Tomcat 5.5.15
* Apache Software Foundation Tomcat 5.5.14
* Apache Software Foundation Tomcat 5.5.13
* Apache Software Foundation Tomcat 5.5.12
* Apache Software Foundation Tomcat 5.5.11
* Apache Software Foundation Tomcat 5.5.10
* Apache Software Foundation Tomcat 5.5.9
* Apache Software Foundation Tomcat 5.5.8
* Apache Software Foundation Tomcat 5.5.7
* Apache Software Foundation Tomcat 5.5.6
* Apache Software Foundation Tomcat 5.5.5
* Apache Software Foundation Tomcat 5.5.4
* Apache Software Foundation Tomcat 5.5.3
* Apache Software Foundation Tomcat 5.5.2
* Apache Software Foundation Tomcat 5.5.1
* Apache Software Foundation Tomcat 5.5
Non-Vulnerable Systems:
* Apache Software Foundation Tomcat 6.0.24
* Apache Software Foundation Tomcat 5.5.29
Exploiting this issue allows attackers to delete or overwrite arbitrary files within the context of the webserver.
Vendor Status:
Apache Software Foundation as issued an update for this vulnerablity.
Patch Availability:
http://httpd.apache.org/download.cgi
CVE Information:
CVE-2009-2901
Disclosure Timeline:
Intial release Apr 17 2012
|
|
blog comments powered by
|