QID 150627
Date Published: 2023-01-10
QID 150627: Tomcat Manager Path Normalization Vulnerability
Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.
A Tomcat Manager login panel was discovered via path normalization. Normalizing a path involves modifying the string that identifies a path or file so that it conforms to a valid path on the target operating system.
QID Detection Logic:
This QID sends a HTTP GET request with /..;/ payload and based on the response confirms if the target is vulnerable.
An attacker can use it to perform path traversal attack and access sensitive information on the server, which may lead to a takeover of the server.
Solution
Customers are advised to configure the reverse proxy to reject paths that contain the Tomcat path parameter character ;.
Vendor References
CVEs related to QID 150627
Software Advisories
| Advisory ID | Software | Component | Link |
|---|