Apache Tomcat Host Manager Cross Site Scripting Vulnerability
BID:29502
Info
Apache Tomcat Host Manager Cross Site Scripting Vulnerability
| Bugtraq ID: | 29502 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1947 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2008 12:00AM |
| Updated: | Apr 13 2015 09:19PM |
| Credit: | Petr Splichal of RedHat <br> |
| Vulnerable: |
WiKID Systems WiKID Server 3.0.4 VMWare VirtualCenter 2.0.2 VMWare VirtualCenter 2.5.Update 3 build 1 VMWare VirtualCenter 2.5 Update 5 VMWare VirtualCenter 2.5 Update 2 VMWare VirtualCenter 2.5 Update 1 VMWare VirtualCenter 2.5 VMWare VirtualCenter 2.0.2 Update 5 VMWare VirtualCenter 2.0.2 Update 4 VMWare VirtualCenter 2.0.2 Update 3 VMWare VirtualCenter 2.0.2 Update 2 VMWare VirtualCenter 2.0.2 Update 1 VMWare vCenter 4.0 VMWare Server 2.0.2 VMWare Server 2.0.1 VMWare Server 2.0 VMWare ESX Server 3.0.3 VMWare ESX Server 3.0.2 VMWare ESX Server 3.0.1 VMWare ESX Server 3.0 VMWare ESX Server 4.0 VMWare ESX Server 3.5 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise Server 10 SP1 Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 10_x86 Sun Solaris 10_sparc Sun OpenSolaris build snv_99 Sun OpenSolaris build snv_96 Sun OpenSolaris build snv_95 Sun OpenSolaris build snv_92 Sun OpenSolaris build snv_91 Sun OpenSolaris build snv_90 Sun OpenSolaris build snv_89 Sun OpenSolaris build snv_88 Sun OpenSolaris build snv_87 Sun OpenSolaris build snv_86 Sun OpenSolaris build snv_85 Sun OpenSolaris build snv_84 Sun OpenSolaris build snv_83 Sun OpenSolaris build snv_82 Sun OpenSolaris build snv_81 Sun OpenSolaris build snv_80 Sun OpenSolaris build snv_78 Sun OpenSolaris build snv_77 Sun OpenSolaris build snv_76 Sun OpenSolaris build snv_68 Sun OpenSolaris build snv_67 Sun OpenSolaris build snv_64 Sun OpenSolaris build snv_61 Sun OpenSolaris build snv_59 Sun OpenSolaris build snv_57 Sun OpenSolaris build snv_50 Sun OpenSolaris build snv_39 Sun OpenSolaris build snv_36 Sun OpenSolaris build snv_29 Sun OpenSolaris build snv_22 Sun OpenSolaris build snv_19 Sun OpenSolaris build snv_13 Sun OpenSolaris build snv_100 Sun OpenSolaris build snv_02 Sun OpenSolaris build snv_01 S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 Redhat Red Hat Network Satellite Server 5.0.1 Redhat Red Hat Network Satellite Server 5.0 Redhat Red Hat Network Satellite (for RHEL 4) 5.1 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Redhat Developer Suite AS4 3 Redhat Application Server WS4 2 Redhat Application Server ES4 2 Redhat Application Server AS4 2 Pardus Linux 2008 0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 HP XP P9000 Performance Advisor 5.4.1 HP HP-UX B.11.31 HP HP-UX B.11.11 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Computer Associates Service Desk 12.1 Avaya Meeting Exchange - Enterprise Edition Avaya Meeting Exchange 5.0 .0.52 Avaya Meeting Exchange 5.0 Avaya Aura Application Enablement Services 4.2.1 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 3.1.6 Avaya Aura Application Enablement Services 3.1.5 Avaya Aura Application Enablement Services 3.1.4 Avaya Aura Application Enablement Services 3.1.3 Avaya Aura Application Enablement Services 4.2 Avaya Aura Application Enablement Services 4.1 Avaya Aura Application Enablement Services 4.0 Avaya Aura Application Enablement Services 3.1 Avaya Aura Application Enablement Services 3.0 Apple Mac OS X Server 10.5.5 Apache Tomcat 6.0.16 Apache Tomcat 6.0.15 Apache Tomcat 6.0.14 Apache Tomcat 6.0.13 Apache Tomcat 6.0.12 Apache Tomcat 6.0.11 Apache Tomcat 6.0.10 Apache Tomcat 6.0.9 Apache Tomcat 6.0.8 Apache Tomcat 6.0.7 Apache Tomcat 6.0.6 Apache Tomcat 6.0.5 Apache Tomcat 6.0.4 Apache Tomcat 6.0.3 Apache Tomcat 6.0.2 Apache Tomcat 6.0.1 Apache Tomcat 6.0 Apache Tomcat 5.5.26 Apache Tomcat 5.5.25 Apache Tomcat 5.5.24 Apache Tomcat 5.5.23 Apache Tomcat 5.5.22 Apache Tomcat 5.5.21 Apache Tomcat 5.5.20 Apache Tomcat 5.5.19 Apache Tomcat 5.5.18 Apache Tomcat 5.5.17 Apache Tomcat 5.5.16 Apache Tomcat 5.5.15 Apache Tomcat 5.5.14 Apache Tomcat 5.5.13 Apache Tomcat 5.5.12 Apache Tomcat 5.5.11 Apache Tomcat 5.5.10 Apache Tomcat 5.5.9 |
| Not Vulnerable: |
WiKID Systems WiKID Server 3.0.5 VMWare VirtualCenter 2.5 Update 6 VMWare vCenter 4.0 Update 1 Sun OpenSolaris build snv_101 HP XP P9000 Performance Advisor 5.5.1 Apache Tomcat 6.0.18 Apache Tomcat 5.5.27 Apache Tomcat 4.1.39 |
Discussion
Apache Tomcat Host Manager Cross Site Scripting Vulnerability
Apache Tomcat is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. The issue affects the Host Manager web application.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
The issue affects the following versions:
Tomcat 5.5.9 through 5.5.26
Tomcat 6.0.0 through 6.0.16
Apache Tomcat is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. The issue affects the Host Manager web application.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
The issue affects the following versions:
Tomcat 5.5.9 through 5.5.26
Tomcat 6.0.0 through 6.0.16
Exploit / POC
Apache Tomcat Host Manager Cross Site Scripting Vulnerability
Attackers can use a browser to exploit this issue.
The following proof of concept is available:
<form action="http://localhost:8080/host-manager/html/add" method="get">
<INPUT TYPE="hidden" NAME='name' VALUE="<script>alert()</script>">
<INPUT TYPE="hidden" NAME='aliases' VALUE="somealias">
<input type="submit">
</form>
Attackers can use a browser to exploit this issue.
The following proof of concept is available:
<form action="http://localhost:8080/host-manager/html/add" method="get">
<INPUT TYPE="hidden" NAME='name' VALUE="<script>alert()</script>">
<INPUT TYPE="hidden" NAME='aliases' VALUE="somealias">
<input type="submit">
</form>
Solution / Fix
Apache Tomcat Host Manager Cross Site Scripting Vulnerability
Solution:
Vendor updates are available. Contact the vendor for details.
Mandriva Linux Mandrake 2008.0
VMWare ESX Server 4.0
HP HP-UX B.11.11
Apple Mac OS X Server 10.5.5
Solution:
Vendor updates are available. Contact the vendor for details.
Mandriva Linux Mandrake 2008.0
-
Mandriva tomcat5-5.5.23-9.2.10.2mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva tomcat5-admin-webapps-5.5.23-9.2.10.2mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva tomcat5-common-lib-5.5.23-9.2.10.2mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva tomcat5-jasper-5.5.23-9.2.10.2mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva tomcat5-jasper-javadoc-5.5.23-9.2.10.2mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva tomcat5-jsp-2.0-api-5.5.23-9.2.10.2mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva tomcat5-jsp-2.0-api-javadoc-5.5.23-9.2.10.2mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva tomcat5-server-lib-5.5.23-9.2.10.2mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva tomcat5-servlet-2.4-api-5.5.23-9.2.10.2mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva tomcat5-servlet-2.4-api-javadoc-5.5.23-9.2.10.2mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva tomcat5-webapps-5.5.23-9.2.10.2mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
VMWare ESX Server 4.0
-
VMWare ESX-4.0.0-update01.zip
https://hostupdate.vmware.com/software/VUM/OFFLINE/release-158-2009111 8-187517/ESX-4.0.0-update01.zip
HP HP-UX B.11.11
-
HP HPUXWSATW-B222-1111.depot
PA-32
http://software.hp.com -
HP HPUXWSATW-B302-64.depot
http://software.hp.com
Apple Mac OS X Server 10.5.5
-
Apple SecUpdSrvr2008-007.dmg
http://www.apple.com/support/downloads/securityupdate2008007serverleop ard.html
References
Apache Tomcat Host Manager Cross Site Scripting Vulnerability
References:
References:
- [Security-announce] UPDATED VMSA-2009-0002.1 VirtualCenter Update 4 and ESX patc (VMware)
- Apache Tomcat 4.x vulnerabilities (Apache)
- Apache Tomcat 5.x vulnerabilities (Apache)
- Apache Tomcat 6.x vulnerabilities (Apache)
- Apache Tomcat Homepage (Apache)
- Release Name: 3.0.5 (WiKID Systems)
- Solution 251986 : Security Vulnerabilities in Tomcat 5.5 may Lead to Cross S (Sun Microsystem)
- TEC503137 (Computer Associates)
- [SECURITY] CVE-2008-1947: Tomcat host-manager XSS vulnerability (Mark Thomas
) - VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release addre (VMware Security Team
) - ASA-2008-401 - tomcat security update (RHSA-2008-0862) (Avaya)
- CVE-2008-1947: Tomcat host-manager XSS vulnerability (Mark Thomas)
- HPSBST02955 rev.1 - HP XP P9000 Performance Advisor Software, 3rd party Software (HP)
- RHSA-2008:0648-10 tomcat security update (Red Hat)