Apache Tomcat Accept-Language Cross Site Scripting Vulnerability
BID:24524
Info
Apache Tomcat Accept-Language Cross Site Scripting Vulnerability
| Bugtraq ID: | 24524 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-1358 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2007 12:00AM |
| Updated: | Aug 05 2010 08:45PM |
| Credit: | Masato Anzai and Toshiharu Sugiyama are credited with the discovery of this vulnerability. <br> |
| Vulnerable: |
Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 10_x86 Sun Solaris 10_sparc Redhat Red Hat Network Satellite Server 5.0 Redhat Network Satellite (for RHEL 4) 5.1 Redhat Network Satellite (for RHEL 4) 4.2 Redhat Network Satellite (for RHEL 3) 4.2 Redhat Fedora 7 Redhat Certificate Server 7.3 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 Computer Associates Cohesion Application Configuration Manager 4.5 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.3.9 Apple Mac OS X 10.4.10 Apple Mac OS X 10.3.9 Apache Tomcat 6.0.13 Apache Tomcat 6.0.12 Apache Tomcat 6.0.11 Apache Tomcat 6.0.10 Apache Tomcat 6.0.5 Apache Tomcat 6.0.4 Apache Tomcat 6.0.3 Apache Tomcat 6.0.2 Apache Tomcat 6.0.1 Apache Tomcat 6.0 Apache Tomcat 5.5.20 Apache Tomcat 5.5.19 Apache Tomcat 5.5.18 Apache Tomcat 5.5.17 Apache Tomcat 5.5.16 Apache Tomcat 5.5.15 Apache Tomcat 5.5.14 Apache Tomcat 5.5.13 Apache Tomcat 5.5.12 Apache Tomcat 5.5.11 Apache Tomcat 5.5.10 Apache Tomcat 5.5.2 Apache Tomcat 5.5.1 Apache Tomcat 5.5 Apache Tomcat 5.0.30 Apache Tomcat 5.0.16 Apache Tomcat 5.0.15 Apache Tomcat 5.0.14 Apache Tomcat 5.0.13 Apache Tomcat 5.0.12 Apache Tomcat 5.0.11 Apache Tomcat 5.0.10 Apache Tomcat 5.0.3 Apache Tomcat 5.0.2 Apache Tomcat 5.0.1 Apache Tomcat 4.1.34 Apache Tomcat 4.1 Apache Tomcat 4.0.6 Apache Tomcat 4.0.5 Apache Tomcat 4.0.4 Apache Tomcat 4.0.3 Apache Tomcat 4.0.2 Apache Tomcat 4.0.1 Apache Tomcat 4.0 Apache Tomcat 5.0 |
| Not Vulnerable: |
Computer Associates Cohesion Application Configuration Manager 4.5 SP1 Apache Tomcat 6.0.6 Apache Tomcat 5.5.21 Apache Tomcat 4.1.36 |
Discussion
Apache Tomcat Accept-Language Cross Site Scripting Vulnerability
Apache Tomcat is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to inject HTML and script code into the browser of an unsuspecting victim. The attacker may then steal cookie-based authentication credentials and launch other attacks.
This issue may have been reported as part of the vulnerabilities described in BID 24058 (Apache Tomcat Documentation Sample Application Multiple Cross-Site Scripting Vulnerabilities). Symantec has not been able to confirm this information. We will update this BID when more information emerges.
Apache Tomcat is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to inject HTML and script code into the browser of an unsuspecting victim. The attacker may then steal cookie-based authentication credentials and launch other attacks.
This issue may have been reported as part of the vulnerabilities described in BID 24058 (Apache Tomcat Documentation Sample Application Multiple Cross-Site Scripting Vulnerabilities). Symantec has not been able to confirm this information. We will update this BID when more information emerges.
Exploit / POC
Apache Tomcat Accept-Language Cross Site Scripting Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Apache Tomcat Accept-Language Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Sun Solaris 9_x86
Apple Mac OS X Server 10.3.9
Apple Mac OS X 10.3.9
Apple Mac OS X 10.4.10
Apple Mac OS X Server 10.4.10
Solution:
Updates are available. Please see the references for more information.
Sun Solaris 9_x86
-
Sun 114017-02
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -114017-02-1 -
Sun 114145-10
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -114145-10-1
Apple Mac OS X Server 10.3.9
-
Apple SecUpdSrvr2007-007Pan.dmg For Mac OS X Server v10.3.9
http://www.apple.com/support/downloads/
Apple Mac OS X 10.3.9
-
Apple SecUpd2007-007Pan.dmg For Mac OS X v10.3.9
http://www.apple.com/support/downloads/
Apple Mac OS X 10.4.10
-
Apple SecUpd2007-007Ti.dmg For Mac OS X v10.4.10 (PowerPC)
http://www.apple.com/support/downloads/ -
Apple SecUpd2007-007Univ.dmg For Mac OS X v10.4.10 (Universal)
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.10
-
Apple SecUpdSrvr2007-007Ti.dmg For Mac OS X Server v10.4.10 (PowerPC)
http://www.apple.com/support/downloads/ -
Apple SecUpdSrvr2007-007Universal.dmg For Mac OS X Server v10.4.10 (Universal)
http://www.apple.com/support/downloads/
References
Apache Tomcat Accept-Language Cross Site Scripting Vulnerability
References:
References:
- Apache Tomcat 4.x vulnerabilities (Apache)
- Apache Tomcat 5.x vulnerabilities (Apache)
- Apache Tomcat 6.x vulnerabilities (Apache)
- Apache Tomcat Homepage (Apache)
- JVN#16535199 (JVN)
- CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1) ("Williams, James K"
) - CVE-2007-1358] Apache Tomcat XSS vulnerability in Accept-Language header process (Mark Thomas)
- HPSBUX02262 SSRT071447 rev. 1 (Hewlett-Packard)
- CA20090123-01: Security Notice for Cohesion Tomcat (Computer Associates)
- RHSA-2008:0261-4 Moderate: Red Hat Network Satellite Server security update (Red Hat)
- RHSA-2008:0524-4 Red Hat Network Satellite Server security update (Red Hat)
- RHSA-2008:0627-2 Low: Red Hat Network Proxy Server security update (Red Hat)
- Security Vulnerabilities in Tomcat 4.0 Shipped with Solaris 9 and 10 (Sun Microsystems)
- Solution 239312 : Security Vulnerabilities in Tomcat 4.0 Shipped with Solaris (Sun)