Apache Tomcat Parameter Processing Remote Information Disclosure Vulnerability
BID:27703
Info
Apache Tomcat Parameter Processing Remote Information Disclosure Vulnerability
| Bugtraq ID: | 27703 |
| Class: | Design Error |
| CVE: |
CVE-2008-0002 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2008 12:00AM |
| Updated: | May 07 2015 05:03PM |
| Credit: | Chitrapandian N of AdventNet Inc. is credited with the discovery of this vulnerability. |
| Vulnerable: |
VMWare VirtualCenter 2.0.2 VMWare VirtualCenter 2.5 Update 5 VMWare VirtualCenter 2.5 Update 2 VMWare VirtualCenter 2.5 Update 1 VMWare VirtualCenter 2.5 VMWare VirtualCenter 2.0.2 Update 5 VMWare VirtualCenter 2.0.2 Update 4 VMWare VirtualCenter 2.0.2 Update 3 VMWare VirtualCenter 2.0.2 Update 2 VMWare VirtualCenter 2.0.2 Update 1 VMWare vCenter 4.0 VMWare Server 2.0.2 VMWare Server 2.0.1 VMWare Server 2.0 VMWare ESX Server 3.0.3 VMWare ESX Server 3.0.2 VMWare ESX Server 3.0.1 VMWare ESX Server 3.0 VMWare ESX Server 4.0 VMWare ESX Server 3.5 SuSE SUSE Linux Enterprise Server 10 SP2 Sun Solaris 10 Redhat Fedora 7 HP XP P9000 Performance Advisor 5.4.1 Gentoo www-servers/tomcat 6.0.15 Gentoo www-servers/tomcat 6.0.14 Gentoo www-servers/tomcat 6.0.13 Gentoo www-servers/tomcat 6.0.12 Gentoo www-servers/tomcat 6.0.11 Gentoo www-servers/tomcat 6.0.10 Gentoo www-servers/tomcat 6.0.9 Gentoo www-servers/tomcat 6.0.8 Gentoo www-servers/tomcat 6.0.7 Gentoo www-servers/tomcat 6.0.6 Gentoo www-servers/tomcat 6.0.5 Gentoo www-servers/tomcat 6.0.4 Gentoo www-servers/tomcat 6.0.3 Gentoo www-servers/tomcat 6.0.2 Gentoo www-servers/tomcat 6.0.1 Gentoo www-servers/tomcat 6.0 Apple Mac OS X Server 10.5.5 Apache Tomcat 6.0.15 Apache Tomcat 6.0.14 Apache Tomcat 6.0.13 Apache Tomcat 6.0.12 Apache Tomcat 6.0.11 Apache Tomcat 6.0.10 Apache Tomcat 6.0.9 Apache Tomcat 6.0.8 Apache Tomcat 6.0.7 Apache Tomcat 6.0.6 Apache Tomcat 6.0.5 |
| Not Vulnerable: |
VMWare VirtualCenter 2.5 Update 6 VMWare vCenter 4.0 Update 1 HP XP P9000 Performance Advisor 5.5.1 Apache Tomcat 6.0.16 |
Discussion
Apache Tomcat Parameter Processing Remote Information Disclosure Vulnerability
Apache Tomcat is prone to a remote information-disclosure vulnerability because the application fails to properly handle exceptions.
Remote attackers can exploit this issue to obtain potentially sensitive information.
The issue affects Tomcat 6.0.5 to 6.0.15.
Apache Tomcat is prone to a remote information-disclosure vulnerability because the application fails to properly handle exceptions.
Remote attackers can exploit this issue to obtain potentially sensitive information.
The issue affects Tomcat 6.0.5 to 6.0.15.
Exploit / POC
Apache Tomcat Parameter Processing Remote Information Disclosure Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache Tomcat Parameter Processing Remote Information Disclosure Vulnerability
Solution:
The vendor has released Tomcat 6.0.16 to address this issue. Contact the vendor for details on obtaining and applying the appropriate updates.
VMWare ESX Server 4.0
VMWare ESX Server 3.5
Apple Mac OS X Server 10.5.5
Apache Tomcat 6.0.10
Apache Tomcat 6.0.11
Apache Tomcat 6.0.12
Apache Tomcat 6.0.13
Apache Tomcat 6.0.14
Apache Tomcat 6.0.15
Apache Tomcat 6.0.5
Apache Tomcat 6.0.6
Apache Tomcat 6.0.7
Apache Tomcat 6.0.8
Apache Tomcat 6.0.9
Solution:
The vendor has released Tomcat 6.0.16 to address this issue. Contact the vendor for details on obtaining and applying the appropriate updates.
VMWare ESX Server 4.0
-
VMWare ESX-4.0.0-update01.zip
https://hostupdate.vmware.com/software/VUM/OFFLINE/release-158-2009111 8-187517/ESX-4.0.0-update01.zip
VMWare ESX Server 3.5
-
VMWare ESX350-201003403-SG.zip
http://download3.vmware.com/software/vi/ESX350-201003403-SG.zip
Apple Mac OS X Server 10.5.5
-
Apple SecUpdSrvr2008-007.dmg
http://www.apple.com/support/downloads/securityupdate2008007serverleop ard.html
Apache Tomcat 6.0.10
-
Apache Software Foundation apache-tomcat-6.0.16.tar.gz
http://apache.mirror.rafal.ca/tomcat/tomcat-6/v6.0.16/bin/apache-tomca t-6.0.16.tar.gz
Apache Tomcat 6.0.11
-
Apache Software Foundation apache-tomcat-6.0.16.tar.gz
http://apache.mirror.rafal.ca/tomcat/tomcat-6/v6.0.16/bin/apache-tomca t-6.0.16.tar.gz
Apache Tomcat 6.0.12
-
Apache Software Foundation apache-tomcat-6.0.16.tar.gz
http://apache.mirror.rafal.ca/tomcat/tomcat-6/v6.0.16/bin/apache-tomca t-6.0.16.tar.gz
Apache Tomcat 6.0.13
-
Apache Software Foundation apache-tomcat-6.0.16.tar.gz
http://apache.mirror.rafal.ca/tomcat/tomcat-6/v6.0.16/bin/apache-tomca t-6.0.16.tar.gz
Apache Tomcat 6.0.14
-
Apache Software Foundation apache-tomcat-6.0.16.tar.gz
http://apache.mirror.rafal.ca/tomcat/tomcat-6/v6.0.16/bin/apache-tomca t-6.0.16.tar.gz
Apache Tomcat 6.0.15
-
Apache Software Foundation apache-tomcat-6.0.16.tar.gz
http://apache.mirror.rafal.ca/tomcat/tomcat-6/v6.0.16/bin/apache-tomca t-6.0.16.tar.gz
Apache Tomcat 6.0.5
-
Apache Software Foundation apache-tomcat-6.0.16.tar.gz
http://apache.mirror.rafal.ca/tomcat/tomcat-6/v6.0.16/bin/apache-tomca t-6.0.16.tar.gz
Apache Tomcat 6.0.6
-
Apache Software Foundation apache-tomcat-6.0.16.tar.gz
http://apache.mirror.rafal.ca/tomcat/tomcat-6/v6.0.16/bin/apache-tomca t-6.0.16.tar.gz
Apache Tomcat 6.0.7
-
Apache Software Foundation apache-tomcat-6.0.16.tar.gz
http://apache.mirror.rafal.ca/tomcat/tomcat-6/v6.0.16/bin/apache-tomca t-6.0.16.tar.gz
Apache Tomcat 6.0.8
-
Apache Software Foundation apache-tomcat-6.0.16.tar.gz
http://apache.mirror.rafal.ca/tomcat/tomcat-6/v6.0.16/bin/apache-tomca t-6.0.16.tar.gz
Apache Tomcat 6.0.9
-
Apache Software Foundation apache-tomcat-6.0.16.tar.gz
http://apache.mirror.rafal.ca/tomcat/tomcat-6/v6.0.16/bin/apache-tomca t-6.0.16.tar.gz
References
Apache Tomcat Parameter Processing Remote Information Disclosure Vulnerability
References:
References:
- Apache Tomcat 6.x vulnerabilities (Apache)
- Apache Tomcat Homepage (Apache)
- Multiple vulnerabilities in Oracle Java Web Console (Oracle)
- Multiple vulnerabilities in Oracle Java Web Console1 (Oracle)
- CVE-2008-0002: Tomcat information disclosure vulnerability (Mark Thomas
) - VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release addre (VMware Security Team
) - HPSBST02955 rev.1 - HP XP P9000 Performance Advisor Software, 3rd party Software (HP)