Apache Tomcat < 5.5.23 / 6.0.10 Directory Traversal Arbitrary File Access

medium Log Correlation Engine Plugin ID 800604

Synopsis

The remote host is vulnerable to a directory traversal flaw.

Description

The remote host is running the Apache Tomcat server. This version of Tomcat is vulnerable to a directory traversal flaw. An attacker exploiting this flaw would only need to be able to send a malformed request to the server. Successful exploitation would result in the attacker being able to read arbitrary files with the permission of the web server process. This can lead to disclosure of source code or confidential data.

Solution

Upgrade to version 5.5.23, 6.0.10 or higher.

See Also

tomcat.apache.org

Plugin Details

Severity: Medium

ID: 800604

Family: Web Servers

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Reference Information

CVE: CVE-2007-0450

BID: 22960