Apache Tomcat CVE-2013-2071 Information Disclosure Vulnerability
BID:59798
Info
Apache Tomcat CVE-2013-2071 Information Disclosure Vulnerability
| Bugtraq ID: | 59798 |
| Class: | Design Error |
| CVE: |
CVE-2013-2071 |
| Remote: | Yes |
| Local: | No |
| Published: | May 10 2013 12:00AM |
| Updated: | May 23 2017 04:26PM |
| Credit: | Apache Tomcat Security Team |
| Vulnerable: |
Ubuntu Ubuntu Linux 13.04 Ubuntu Ubuntu Linux 12.10 Ubuntu Ubuntu Linux 12.04 LTS Ubuntu Ubuntu Linux 10.04 LTS Redhat JBoss Enterprise Web Server 2.0.0 Oracle Transportation Management 6.3.2 Oracle Transportation Management 6.3.1 Oracle Transportation Management 6.3 Oracle Oracle Transportation Management 6.2 Oracle Oracle Transportation Management 6.1 Oracle Oracle Transportation Management 6.0 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Apache Tomcat 7.0.32 Apache Tomcat 7.0.31 Apache Tomcat 7.0.30 Apache Tomcat 7.0.29 Apache Tomcat 7.0.28 Apache Tomcat 7.0.27 Apache Tomcat 7.0.26 Apache Tomcat 7.0.25 Apache Tomcat 7.0.24 Apache Tomcat 7.0.23 Apache Tomcat 7.0.17 Apache Tomcat 7.0.16 Apache Tomcat 7.0.15 Apache Tomcat 7.0.14 Apache Tomcat 7.0.13 Apache Tomcat 7.0.12 Apache Tomcat 7.0.9 Apache Tomcat 7.0.8 Apache Tomcat 7.0.7 Apache Tomcat 7.0.6 Apache Tomcat 7.0.4 Apache Tomcat 7.0.3 Apache Tomcat 7.0.2 Apache Tomcat 7.0.1 Apache Tomcat 7.0 beta Apache Tomcat 7.0 Apache Tomcat 7.0.5 Apache Tomcat 7.0.22 Apache Tomcat 7.0.21 Apache Tomcat 7.0.20 Apache Tomcat 7.0.19 Apache Tomcat 7.0.18 Apache Tomcat 7.0.17 Apache Tomcat 7.0.11 Apache Tomcat 7.0.10 Apache Tomcat 7.0 |
| Not Vulnerable: |
Redhat JBoss Enterprise Web Server 2.0.1 Apache Tomcat 7.0.40 |
Discussion
Apache Tomcat CVE-2013-2071 Information Disclosure Vulnerability
Apache Tomcat is prone to a remote information-disclosure vulnerability.
Remote attackers can exploit this issue to obtain sensitive information.
Tomcat versions 7.0.0 through 7.0.39 are vulnerable.
Apache Tomcat is prone to a remote information-disclosure vulnerability.
Remote attackers can exploit this issue to obtain sensitive information.
Tomcat versions 7.0.0 through 7.0.39 are vulnerable.
Exploit / POC
Apache Tomcat CVE-2013-2071 Information Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache Tomcat CVE-2013-2071 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Tomcat CVE-2013-2071 Information Disclosure Vulnerability
References:
References:
- [CVE-2013-2071] runtime exception in onComplete of AsyncListener, will make org. (Apache Software Foundation)
- Apache Tomcat Homepage (Apache)
- HPSBMU02966 rev.1 - HP Operations Orchestration, Unauthorized Access to Informat (HP)
- Information disclosure CVE-2013-2071 (Apache Software Foundation)
- Oracle Critical Patch Update Advisory - January 2014 (Oracle)