Apache Tomcat JK Connector CVE-2018-1323 Directory Traversal Vulnerability
BID:103389
CVE-2018-1323 |Info
Apache Tomcat JK Connector CVE-2018-1323 Directory Traversal Vulnerability
| Bugtraq ID: | 103389 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-1323 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 12 2018 12:00AM |
| Updated: | Mar 12 2018 12:00AM |
| Credit: | Alphan Yavas from Biznet Bilisim A.S. |
| Vulnerable: |
Redhat JBoss Core Services 1 Apache Tomcat JK Connector 1.2.42 Apache Tomcat JK Connector 1.2.41 Apache Tomcat JK Connector 1.2 |
| Not Vulnerable: |
Apache Tomcat JK Connector 1.2.43 |
Discussion
Apache Tomcat JK Connector CVE-2018-1323 Directory Traversal Vulnerability
Apache Tomcat JK Connector is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input.
Remote attackers may use a specially crafted request with directory-traversal sequences ('../') to retrieve arbitrary files from the affected system in the context of the application. Information obtained could aid in further attacks.
Apache Tomcat JK Connector 1.2.0 through 1.2.42 are vulnerable.
Apache Tomcat JK Connector is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input.
Remote attackers may use a specially crafted request with directory-traversal sequences ('../') to retrieve arbitrary files from the affected system in the context of the application. Information obtained could aid in further attacks.
Apache Tomcat JK Connector 1.2.0 through 1.2.42 are vulnerable.
Exploit / POC
Apache Tomcat JK Connector CVE-2018-1323 Directory Traversal Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache Tomcat JK Connector CVE-2018-1323 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.