Apache Tomcat Information Disclosure Vulnerability
BID:19106
CVE-2006-3835 |Info
Apache Tomcat Information Disclosure Vulnerability
| Bugtraq ID: | 19106 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3835 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2006 12:00AM |
| Updated: | Aug 05 2010 08:45PM |
| Credit: | ScanAlert's Enterprise Services Team is credited with the discovery of this vulnerability. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 10_x86 Sun Solaris 10_sparc Redhat Red Hat Network Satellite Server 5.0 Redhat Red Hat Network Satellite Server 4.2 Redhat Red Hat Network Satellite Server 4.1 Redhat Red Hat Network Satellite Server 4.0 Redhat Network Satellite (for RHEL 4) 4.2 Redhat Network Satellite (for RHEL 3) 4.2 Redhat Certificate Server 7.3 Novell GroupWise Mobile Server 1.0 Computer Associates Cohesion Application Configuration Manager 4.5 Avaya Aura Application Enablement Services 4.0 Avaya Aura Application Enablement Services 3.1 Apache Tomcat 5.5.16 Apache Tomcat 5.5.12 Apache Tomcat 5.5.9 Apache Tomcat 5.5.7 Apache Tomcat 5.0.28 |
| Not Vulnerable: |
Computer Associates Cohesion Application Configuration Manager 4.5 SP1 Apache Tomcat 5.5.17 |
Discussion
Apache Tomcat Information Disclosure Vulnerability
Apache Tomcat is prone to an information-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to reveal a complete directory listing from any directory. Information obtained may aid in further attacks. Reports indicate that this issue may also allow attackers to obtain the source code of script files.
Apache Tomcat 5.028, 5.5.23, 5.5.9, and 5.5.7 are vulnerable to this issue; other versions may also be affected.
Novell GroupWise Mobile Server 1.0 or other versions bundled with Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2 ship with an affected version of Tomcat and are vulnerable as well.
Apache Tomcat is prone to an information-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to reveal a complete directory listing from any directory. Information obtained may aid in further attacks. Reports indicate that this issue may also allow attackers to obtain the source code of script files.
Apache Tomcat 5.028, 5.5.23, 5.5.9, and 5.5.7 are vulnerable to this issue; other versions may also be affected.
Novell GroupWise Mobile Server 1.0 or other versions bundled with Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2 ship with an affected version of Tomcat and are vulnerable as well.
Exploit / POC
Apache Tomcat Information Disclosure Vulnerability
Attackers can use a browser to exploit this issue.
The following proof-of-concept URI is available:
Attackers can use a browser to exploit this issue.
The following proof-of-concept URI is available:
Solution / Fix
Apache Tomcat Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Sun Solaris 9_x86
Solution:
Updates are available. Please see the references for more information.
Sun Solaris 9_x86
References
Apache Tomcat Information Disclosure Vulnerability
References:
References:
- Apache Tomcat Homepage (Apache)
- ASA-2007-206 - tomcat security update (Avaya)
- Directory Listing in Apache Tomcat 5.x.x (neohapsis)
- Mobile Messaging with GroupWise Mobile Server, Powered by Intellisync (Novell)
- CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1) ("Williams, James K"
) - SEC Consult SA-20070509-0 :: Multiple vulnerabilites in Nokia Intellisync Mobile (Johannes Greil
) - CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Computer Associates)
- CA20090123-01: Security Notice for Cohesion Tomcat (Computer Associates)
- RHSA-2007:1069-5 Moderate: tomcat security update for Red Hat Network Satellite (Red Hat)
- RHSA-2008:0261-4 Moderate: Red Hat Network Satellite Server security update (Red Hat)
- RHSA-2008:0524-4 Red Hat Network Satellite Server security update (Red Hat)
- Security Vulnerabilities in Tomcat 4.0 Shipped with Solaris 9 and 10 (Sun Microsystems)