Apache Tomcat CVE-2017-15706 Remote Security Weakness
BID:103069
CVE-2017-15706 |Info
Apache Tomcat CVE-2017-15706 Remote Security Weakness
| Bugtraq ID: | 103069 |
| Class: | Unknown |
| CVE: |
CVE-2017-15706 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 31 2018 12:00AM |
| Updated: | Nov 09 2018 04:00AM |
| Credit: | Michael Grenier |
| Vulnerable: |
Oracle Solaris 11.3 Bluecoat Director 6.1 Apache Tomcat 9.0.1 Apache Tomcat 8.5.23 Apache Tomcat 8.5.16 Apache Tomcat 8.5.15 Apache Tomcat 8.5.14 Apache Tomcat 8.5.13 Apache Tomcat 8.5.12 Apache Tomcat 8.5.11 Apache Tomcat 8.5.9 Apache Tomcat 8.5.8 Apache Tomcat 8.5.7 Apache Tomcat 8.5.6 Apache Tomcat 8.0.47 Apache Tomcat 8.0.45 Apache Tomcat 7.0.82 Apache Tomcat 7.0.81 Apache Tomcat 7.0.80 Apache Tomcat 7.0.79 Apache Tomcat 9.0.0.M22 |
| Not Vulnerable: | |
Discussion
Apache Tomcat CVE-2017-15706 Remote Security Weakness
Apache Tomcat is prone to a remote security weakness.
Little is known about this issue or its effects at this time. We will update this BID as more information emerges.
Apache Tomcat 9.0.0.M22 through 9.0.1, 8.5.16 through 8.5.23, 8.0.45 through 8.0.47 and 7.0.79 through 7.0.82 are vulnerable.
Apache Tomcat is prone to a remote security weakness.
Little is known about this issue or its effects at this time. We will update this BID as more information emerges.
Apache Tomcat 9.0.0.M22 through 9.0.1, 8.5.16 through 8.5.23, 8.0.45 through 8.0.47 and 7.0.79 through 7.0.82 are vulnerable.
Exploit / POC
Apache Tomcat CVE-2017-15706 Remote Security Weakness
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache Tomcat CVE-2017-15706 Remote Security Weakness
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Tomcat CVE-2017-15706 Remote Security Weakness
References:
References:
- Apache Homepage (Apache)
- Apache Tomcat 9.x vulnerabilities (Apache)
- Bug 1540828 - (CVE-2017-15706) CVE-2017-15706 tomcat: Incorrect documentation o (Redhat)
- Bug 61201 - CGIServlet adds too much to the SCRIPT_NAME environment variable if (Apache)
- CVE-2017-15706 (Redhat)
- Oracle Solaris Third Party Bulletin - April 2018 (Oracle)
- SYMSA1463: Apache Tomcat Vulnerabilities Jan-Aug 2018 (Symantec)