CVE-2009-2901
Summary
| CVE | CVE-2009-2901 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-01-28 20:30:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Tomcat | 5.5.0 | All | All | All |
| Application | Apache | Tomcat | 5.5.1 | All | All | All |
| Application | Apache | Tomcat | 5.5.10 | All | All | All |
| Application | Apache | Tomcat | 5.5.11 | All | All | All |
| Application | Apache | Tomcat | 5.5.12 | All | All | All |
| Application | Apache | Tomcat | 5.5.13 | All | All | All |
| Application | Apache | Tomcat | 5.5.14 | All | All | All |
| Application | Apache | Tomcat | 5.5.15 | All | All | All |
| Application | Apache | Tomcat | 5.5.16 | All | All | All |
| Application | Apache | Tomcat | 5.5.17 | All | All | All |
| Application | Apache | Tomcat | 5.5.18 | All | All | All |
| Application | Apache | Tomcat | 5.5.19 | All | All | All |
| Application | Apache | Tomcat | 5.5.2 | All | All | All |
| Application | Apache | Tomcat | 5.5.20 | All | All | All |
| Application | Apache | Tomcat | 5.5.21 | All | All | All |
| Application | Apache | Tomcat | 5.5.22 | All | All | All |
| Application | Apache | Tomcat | 5.5.23 | All | All | All |
| Application | Apache | Tomcat | 5.5.24 | All | All | All |
| Application | Apache | Tomcat | 5.5.25 | All | All | All |
| Application | Apache | Tomcat | 5.5.26 | All | All | All |
| Application | Apache | Tomcat | 5.5.27 | All | All | All |
| Application | Apache | Tomcat | 5.5.28 | All | All | All |
| Application | Apache | Tomcat | 5.5.3 | All | All | All |
| Application | Apache | Tomcat | 5.5.4 | All | All | All |
| Application | Apache | Tomcat | 5.5.5 | All | All | All |
| Application | Apache | Tomcat | 5.5.6 | All | All | All |
| Application | Apache | Tomcat | 5.5.7 | All | All | All |
| Application | Apache | Tomcat | 5.5.8 | All | All | All |
| Application | Apache | Tomcat | 5.5.9 | All | All | All |
| Application | Apache | Tomcat | 6.0 | All | All | All |
| Application | Apache | Tomcat | 6.0.0 | All | All | All |
| Application | Apache | Tomcat | 6.0.1 | All | All | All |
| Application | Apache | Tomcat | 6.0.10 | All | All | All |
| Application | Apache | Tomcat | 6.0.11 | All | All | All |
| Application | Apache | Tomcat | 6.0.12 | All | All | All |
| Application | Apache | Tomcat | 6.0.13 | All | All | All |
| Application | Apache | Tomcat | 6.0.14 | All | All | All |
| Application | Apache | Tomcat | 6.0.15 | All | All | All |
| Application | Apache | Tomcat | 6.0.16 | All | All | All |
| Application | Apache | Tomcat | 6.0.17 | All | All | All |
| Application | Apache | Tomcat | 6.0.18 | All | All | All |
| Application | Apache | Tomcat | 6.0.19 | All | All | All |
| Application | Apache | Tomcat | 6.0.2 | All | All | All |
| Application | Apache | Tomcat | 6.0.20 | All | All | All |
| Application | Apache | Tomcat | 6.0.3 | All | All | All |
| Application | Apache | Tomcat | 6.0.4 | All | All | All |
| Application | Apache | Tomcat | 6.0.5 | All | All | All |
| Application | Apache | Tomcat | 6.0.6 | All | All | All |
| Application | Apache | Tomcat | 6.0.7 | All | All | All |
| Application | Apache | Tomcat | 6.0.8 | All | All | All |
| Application | Apache | Tomcat | 6.0.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Apache Tomcat 5 WAR Deployment Directory Traversal Weaknesses and Security Issue - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| VMware vCenter Server 4.1 Update 1 Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | |
| '[security bulletin] HPSBMA02535 SSRT100029 rev.1 - HP Performance Manager, Remote Unauthorized Acces' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SUSE Update for Multiple Packages - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| USN-899-1: Tomcat vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | ubuntu.com | |
| openSUSE-SU-2012:1701-1: moderate: update for tomcat | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| openSUSE-SU-2012:1700-1: moderate: update for tomcat6 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| VMSA-2011-0003 | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | |
| [Apache-SVN] Revision 902650 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | Patch |
| [Apache-SVN] Revision 892815 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | Patch |
| Security Advisories | Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:008 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| APPLE-SA-2010-03-29-1 Security Update 2010-002 / Mac OS X v10.6.3 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| SecurityTracker: Tomcat Undeploy Failure May Allow Remote Users to Access Files | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Apache Tomcat - Apache Tomcat 5 vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | Patch, Vendor Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| openSUSE-SU-2013:0147-1: moderate: tomcat6 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Security Advisories | Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Apache Tomcat WAR Deployment Directory Traversal Weaknesses and Security Issue - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| About the security content of Security Update 2010-002 / Mac OS X v10.6.3 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Apache Tomcat® - Apache Tomcat 6 vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | Patch, Vendor Advisory |
| VMware vCenter / ESX Server Apache Tomcat Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Ubuntu update for tomcat6 - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| '[security bulletin] HPSBOV02762 SSRT100825 rev.1 - HP Secure Web Server (SWS) for OpenVMS running CS' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| '[security bulletin] HPSBST02955 rev.1 - HP XP P9000 Performance Advisor Software, 3rd party Software' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Apache Tomcat Directory Host Appbase Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2010-03-02 | Tomas Hoger | Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-2901 This issue did not affect Tomcat versions running on Linux or Solaris systems. This issue is fixed in the tomcat5 and tomcat6 packages released with JBoss Enterprise Web Server 1.0.1 for Windows. |
There are currently no legacy QID mappings associated with this CVE.