Apache Tomcat/5.5.35 Exploit

  • If you need help on building or configuring Tomcat or other help on following the instructions to mitigate the known vulnerabilities listed here, please send your questions to the public Tomcat
  • Tomcat mailing lists are available at the Tomcat project web site: [email protected] for general questions related to configuring and using Tomcat [email protected] for developers working on Tomcat Thanks for using Tomcat!
  • It is possible for a specially crafted message to result in arbitrary content being injected into the HTTP response.
  • In some circumstances disabling renegotiation may result in some clients being unable to access the application.
  • It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content.
  • References: AJP Connector documentation (Tomcat 5.5) workers.properties configuration (mod_jk) released 1 Feb 2011 Fixed in Apache Tomcat 5.5.32 Low: Cross-site scripting CVE-2011-0013 The HTML Manager interface displayed web application provided data,
  • Affects: 5.0.0-5.0.30, 5.5.0-5.5.24 Low: Cross-site scripting CVE-2007-2450 The Manager and Host Manager web applications did not escape user provided data before including it in the output.

Another strange thing that appeared to happen previously, was the fact that I could send emails to the council and various people, yet with this one particular department, some of the Apache Tomcat Security Vulnerabilities It can be found on the local filesystem at: $CATALINA_HOME/webapps/ROOT/index.jsp where "$CATALINA_HOME" is the root of the Tomcat installation directory. Applications that use the raw header values directly should not assume that the headers conform to RFC 2616 and should filter the values appropriately. This was first reported to the Tomcat security team on 2 Mar 2009 and made public on 4 Jun 2009.

Apache Tomcat Security Vulnerabilities

The following Java system properties have been added to Tomcat to provide additional control of the handling of path delimiters in URLs (both options default to false): org.apache.tomcat.util.buf.UDecoder.ALLOW_ENCODED_SLASH: true|false org.apache.catalina.connector.CoyoteAdapter.ALLOW_BACKSLASH: true|false have a peek at these guys A workaround was implemented in revision 904851 that provided the new allowUnsafeLegacyRenegotiation attribute. Affects: 5.5.0-5.5.29 released 20 Apr 2010 Fixed in Apache Tomcat 5.5.29 Low: Arbitrary file deletion and/or alteration on deploy CVE-2009-2693 When deploying WAR files, the WAR files were not checked for This was fixed in revisions 681156 and 781542. Apache Tomcat Input Validation Security Bypass Vulnerability

To workaround this until a fix is available in JSSE, a new connector attribute allowUnsafeLegacyRenegotiation has been added to the BIO connector. Index of /dist/tomcat/tomcat-5/v5.5.27/bin Name Last modified Size Description Parent Directory - apache-tomcat-5.5.27-admin.tar.gz 2008-09-05 22:09 2.3M apache-tomcat-5.5.27-admin.tar.gz.asc 2008-09-05 22:09 194 apache-tomcat-5.5.27-admin.tar.gz.md5 2008-09-05 22:13 68 apache-tomcat-5.5.27-admin.zip 2008-09-05 22:09 2.3M apache-tomcat-5.5.27-admin.zip.asc 2008-09-05 22:09 194 For example, deploying and undeploying ...war allows an attacker to cause the deletion of the current contents of the host's work directory which may cause problems for currently running applications. check over here User passwords are visible to administrators with JMX access and/or administrators with read access to the tomcat-users.xml file.

Affects: 5.5.10-5.5.20 (5.0.x unknown) not released Fixed in Apache Tomcat 5.5.18, 5.0.SVN Moderate: Cross-site scripting CVE-2006-7195 The implicit-objects.jsp in the examples webapp displayed a number of unfiltered header values. Apache Tomcat Multiple Content Length Headers Information Disclosure Vulnerability http://www.microsoft.com/en-gb/download/details.aspx?id=29224 You will need to enter a few pieces of info to set it up. Users are defined in $CATALINA_HOME/conf/tomcat-users.xml.

The version of tar on Solaris and Mac OS X will not work with these files.

This was identified by Wilfried Weissmann on 20 July 2011 and made public on 12 August 2011.

