Apache Tomcat Web.XML File Contents Disclosure Vulnerability
BID:6722
Info
Apache Tomcat Web.XML File Contents Disclosure Vulnerability
| Bugtraq ID: | 6722 |
| Class: | Access Validation Error |
| CVE: |
CVE-2003-0043 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 26 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | This vulnerability was reported by the Jakarta Tomcat Team. |
| Vulnerable: |
Apache Tomcat 3.3.1 Apache Tomcat 3.3 Apache Tomcat 3.2.4 Apache Tomcat 3.2.3 Apache Tomcat 3.2.1 Apache Tomcat 3.2 Apache Tomcat 3.1.1 Apache Tomcat 3.1 Apache Tomcat 3.0 |
| Not Vulnerable: |
Apache Tomcat 3.3.1 a |
Discussion
Apache Tomcat Web.XML File Contents Disclosure Vulnerability
Apache Tomcat is prone to a file disclosure vulnerability when used with JDK 1.3.1 or earlier.
Apache Tomcat may permit malicious web applications to read the contents of some files. It is possible to create a malicious 'web.xml' file which is capable of reading parts of files. Any files that have content that can be read as part of a XML document would be disclosed to an attacker.
This may result in disclosure of sensitive information.
Apache Tomcat is prone to a file disclosure vulnerability when used with JDK 1.3.1 or earlier.
Apache Tomcat may permit malicious web applications to read the contents of some files. It is possible to create a malicious 'web.xml' file which is capable of reading parts of files. Any files that have content that can be read as part of a XML document would be disclosed to an attacker.
This may result in disclosure of sensitive information.
Exploit / POC
Apache Tomcat Web.XML File Contents Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apache Tomcat Web.XML File Contents Disclosure Vulnerability
Solution:
HP has released an advisory (HPSBUX0303-249) that contains fixes to address this issue.
This issue has been addressed in Apache Tomcat 3.3.1a.
Fixes are available:
Apache Tomcat 3.0
Apache Tomcat 3.1
Apache Tomcat 3.1.1
Apache Tomcat 3.2
Apache Tomcat 3.2.1
Apache Tomcat 3.2.3
Apache Tomcat 3.2.4
Apache Tomcat 3.3
Apache Tomcat 3.3.1
Solution:
HP has released an advisory (HPSBUX0303-249) that contains fixes to address this issue.
This issue has been addressed in Apache Tomcat 3.3.1a.
Fixes are available:
Apache Tomcat 3.0
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
Apache Tomcat 3.1
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
Apache Tomcat 3.1.1
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
Apache Tomcat 3.2
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
Apache Tomcat 3.2.1
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
Apache Tomcat 3.2.3
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
Apache Tomcat 3.2.4
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
Apache Tomcat 3.3
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/ -
Debian libapache-mod-jk_3.3a-4woody1_i386.deb
http://security.debian.org/pool/updates/contrib/t/tomcat/libapache-mod -jk_3.3a-4woody1_i386.deb -
Debian tomcat_3.3a-4woody1_all.deb
http://security.debian.org/pool/updates/contrib/t/tomcat/tomcat_3.3a-4 woody1_all.deb
Apache Tomcat 3.3.1
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
References
Apache Tomcat Web.XML File Contents Disclosure Vulnerability
References:
References:
- Apache Software Foundation Homepage (Apache Software Foundation)
- Tomcat Homepage (Apache Software Foundation)