Home > Apache Tomcat > Apache Tomcat 4.1.24 Error Report

Apache Tomcat 4.1.24 Error Report

If an attacker can do this then the server is already compromised. This was fixed in revisions 782763 and 783292. NOTE: this vulnerability exists because of an incomplete fix for CVE-2005-2090. 5 CVE-2012-5568 16 DoS 2012-11-30 2013-03-07 5.0 None Remote Low Not required None None Partial Apache Tomcat through 7.0.x allows Affects: 4.0.0-4.0.1 Fixed in Apache Tomcat 4.0.0 Moderate: Security manager bypass CVE-2002-0493 If errors are encountered during the parsing of web.xml and Tomcat is configured to use a security manager it More Help

It can not be reproduced using Windows 2000 SP4 with latest patches and Tomcat 4.0.4 with JDK 1.3.1. This issue may be mitigated by undeploying the examples web application. Please send us an email to [email protected] with this issue in order for us to be able to resolve this issue. Affects: 4.1.32-4.1.34 (4.0.x unknown) Fixed in Apache Tomcat 4.1.32 Low: Information disclosure CVE-2008-3271 Bug 25835 can, in rare circumstances - this has only been reproduced using a debugger to force a

Affects: 4.1.32-4.1.34 (4.0.x unknown) Fixed in Apache Tomcat 4.1.32 Low: Information disclosure CVE-2008-3271 Bug 25835 can, in rare circumstances - this has only been reproduced using a debugger to force a

When Tomcat is used behind a proxy (including, but not limited to, Apache HTTP server with mod_proxy and mod_jk) configured to only proxy some contexts, a HTTP request containing strings like The new lines in this URL appear to the client to be the end of the header section. In some circumstances this lead to the leaking of information such as session ID to an attacker.

Tomcat now returns 400 for requests with multiple content-length headers. Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path This enabled a XSS attack.

  A sequence of such requests will cause all request processing threads, and hence Tomcat as a whole, to become unresponsive.
  Each vulnerability is given a security impact rating by the Apache Tomcat security team — please note that this rating may vary from platform to platform.
  • Affects: 4.0.0-4.0.6 Low: Information disclosure CVE-2002-2006 The snoop and trouble shooting servlets installed as part of the examples include output that identifies the Tomcat installation path.
NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3544. Apache Tomcat before 6.0.39, 7.x before

This exposes a directory traversal vulnerability when the connector uses URIEncoding="UTF-8". Failure to reject the null byte enables an attacker to obtain the source for any JSP page in these contexts.

Please try the request again. The semicolon (;) is the separator for path parameters so inserting one before a file name changes the request into a request for a directory with a path parameter. Affects: 4.0.0-4.0.6, 4.1.0-4.1.34 Fixed in Apache Tomcat 4.1.35 Low: Information disclosure CVE-2008-4308 Bug 40771 may result in the disclosure of POSTed content from a previous request. get redirected here Applications that use the raw header values directly should not assume that the headers conform to RFC 2616 and should filter the values appropriately.

The following Java system properties have been added to Tomcat to provide additional control of the handling of path delimiters in URLs (both options default to false): org.apache.tomcat.util.buf.UDecoder.ALLOW_ENCODED_SLASH: true|false org.apache.catalina.connector.CoyoteAdapter.ALLOW_BACKSLASH: true|false

If a context is configured with allowLinking="true" then the directory traversal vulnerability is extended to the entire file system of the host server.

This is a variation of CVE-2002-1148 Affects: 4.0.0-4.0.5, 4.1.0-4.1.12 Moderate: Cross-site scripting CVE-2002-0682 A specially crafted URL using the invoker servlet and various internal classess causes Tomcat to throw an exception If directory listings are enabled, the number of files in each directory should be kepp to a minimum. This was fixed in revision 781382. useful reference The remaining part of the URL, including the script elements, is treated as part of the response body and the client executes the script.

Affects: 4.0.0-4.0.6, 4.1.0-4.1.36 Low: Cross-site scripting CVE-2007-2450 The Manager web application did not escape user provided data before including it in the output. Not a vulnerability in Tomcat Important: Directory traversal CVE-2008-2938 Originally reported as a Tomcat vulnerability the root cause of this issue is that the JVM does not correctly decode UTF-8 encoded Copyright © 1999-2016, The Apache Software Foundation Apache Tomcat, Tomcat, Apache, the Apache feather, and the Apache Tomcat project logo are trademarks of the Apache Software Foundation. Tomcat permits '\', '%2F' and '%5C' as path delimiters.

Support Apple Support Communities Shop the Apple Online Store (1-800-MY-APPLE), visit an Apple Retail Store, or find a reseller. Affects: 4.0.0-4.0.6, 4.1.0-4.1.31 Important: Denial of service CVE-2005-3510 The root cause is the relatively expensive calls required to generate the content for the directory listings. Affects: 4.1.0-4.1.39 Low: Information disclosure CVE-2009-0783 Bugs 29936 and 45933 allowed a web application to replace the XML parser used by Tomcat to process web.xml and tld files. Users are advised to use the default, supported Coyote AJP connector which does not exhibit this issue.

Affects: 4.1.0-4.1.31 Important: Information disclosure CVE-2007-1858 The default SSL configuration permitted the use of insecure cipher suites including the anonymous cipher suite. Will not be fixed in Apache Tomcat 4.1.x Moderate: Information disclosure CVE-2005-4836 The deprecated HTTP/1.1 connector does not reject request URIs containing null bytes when used with contexts that are configured Affects: 4.0.1-4.0.6, 4.1.0-4.1.36 Moderate: Cross-site scripting CVE-2007-1355 The JSP and Servlet included in the sample application within the Tomcat documentation webapp did not escape user provided data before including it in NOTE: the vendor disputes the significance of this report, stating that "the Apache Tomcat Security team has not accepted any reports of CSRF attacks against the Manager application ...

