Apache Tomcat POST Data Information Disclosure Vulnerability
BID:33913
Info
Apache Tomcat POST Data Information Disclosure Vulnerability
| Bugtraq ID: | 33913 |
| Class: | Design Error |
| CVE: |
CVE-2008-4308 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2009 12:00AM |
| Updated: | Feb 26 2009 05:07PM |
| Credit: | Fujitsu |
| Vulnerable: |
Fujitsu INTERSTAGE Studio Standard-J Edition 9.0 Fujitsu INTERSTAGE Studio Enterprise Edition 9.0 Fujitsu INTERSTAGE Application Server Standard-J Edition 9.0 A Fujitsu INTERSTAGE Application Server Standard-J Edition 9.0 Fujitsu INTERSTAGE Application Server Enterprise Edition 9.0 A Fujitsu INTERSTAGE Application Server Enterprise Edition 9.0 Apache Tomcat 5.5.20 Apache Tomcat 5.5.19 Apache Tomcat 5.5.18 Apache Tomcat 5.5.17 Apache Tomcat 5.5.16 Apache Tomcat 5.5.15 Apache Tomcat 5.5.14 Apache Tomcat 5.5.13 Apache Tomcat 5.5.12 Apache Tomcat 5.5.11 Apache Tomcat 5.5.10 Apache Tomcat 4.1.34 Apache Tomcat 4.1.32 |
| Not Vulnerable: |
Apache Tomcat 5.5.21 Apache Tomcat 4.1.35 |
Discussion
Apache Tomcat POST Data Information Disclosure Vulnerability
Apache Tomcat is prone to a remote information-disclosure vulnerability.
Remote attackers can exploit this issue to obtain sensitive data stored on the server. Information obtained may lead to further attacks.
The following versions are affected:
Apache Tomcat 4.1.32 through 4.1.34
Apache Tomcat 5.5.10 through 5.5.20
NOTE: Apache Tomcat 6.x is not affected.
Apache Tomcat is prone to a remote information-disclosure vulnerability.
Remote attackers can exploit this issue to obtain sensitive data stored on the server. Information obtained may lead to further attacks.
The following versions are affected:
Apache Tomcat 4.1.32 through 4.1.34
Apache Tomcat 5.5.10 through 5.5.20
NOTE: Apache Tomcat 6.x is not affected.
Exploit / POC
Apache Tomcat POST Data Information Disclosure Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
Apache Tomcat POST Data Information Disclosure Vulnerability
Solution:
The vendor released updates. Please see the references for more information.
Solution:
The vendor released updates. Please see the references for more information.
References
Apache Tomcat POST Data Information Disclosure Vulnerability
References:
References:
- Apache Tomcat 4.x vulnerabilities (Apache)
- Apache Tomcat 5.x vulnerabilities (Apache)
- Apache Tomcat Homepage (Apache)
- Can't read POST data from within a filter or valve (Michael Dufel)
- CVE-2008-4308: Tomcat information disclosure vulnerability (Mark Thomas
) - CVE-2008-4308: Tomcat information disclosure vulnerability (Apache Software Foundation)
- Interstage Application Server: Others Information Disclosure Vulnerability(CVE-2 (Fujitsu)