QID 995389
Date Published: 2023-09-25
QID 995389: Java (Maven) Security Update for org.apache.tomcat:tomcat-juli (GHSA-w65j-cmqc-37p2)
The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-w65j-cmqc-37p2 for updates and patch information.
Vendor References
- GHSA-w65j-cmqc-37p2 -
github.com/advisories/GHSA-w65j-cmqc-37p2
CVEs related to QID 995389
Software Advisories
| Advisory ID | Software | Component | Link |
|---|