Tomcat now returns 400 for requests with multiple content-length headers. This allows an attacker to create arbitrary content outside of the web root by including entries such as ../../bin/catalina.sh in the WAR. This issue was disclosed to the Tomcat security team by [email protected] from the Baidu Security Team on 4 June 2014 and made public on 9 April 2015.

CVE-2012-4431: Fix bypass of CsrfPreventionFilter when there is no session.

Apache Tomcat Security Vulnerabilities

This enabled a malicious web application to bypass the file access constraints imposed by the security manager via the use of external XML entities. This issue was identified by the Tomcat security team on 27 February 2014 and made public on 27 May 2014. Correctly handle multi-level contexts when antiResourceLocking is enabled. Thank you. 11 February 2016 Fixed in Apache Tomcat 6.0.45 Low: Limited directory traversal CVE-2015-5174 This issue only affects users running untrusted web applications under a security manager.

The following Java system properties have been added to Tomcat to provide additional control of the handling of path delimiters in URLs (both options default to false): org.apache.tomcat.util.buf.UDecoder.ALLOW_ENCODED_SLASH: true|false org.apache.catalina.connector.CoyoteAdapter.ALLOW_BACKSLASH: true|false

This was identified by Wilfried Weissmann on 20 July 2011 and made public on 12 August 2011. Affects: 6.0.0 to 6.0.44 Low: Security Manager bypass CVE-2016-0706 This issue only affects users running untrusted web applications under a security manager. Requires JRE that supports RFC 5746.

Note that paths starting with "/../" were correctly rejected.

  • Affects: 6.0.0-6.0.29 released 9 Jul 2010 Fixed in Apache Tomcat 6.0.28 Important: Remote Denial Of Service and Information Disclosure Vulnerability CVE-2010-2227 Several flaws in the handling of the 'Transfer-Encoding' header were
  • Make command names case-insensitive.
  • I didnt save the JSP file in the category of 'ALL FILES' while saving the file from notepad.
  • This issue may be mitigated by logging out (closing the browser) of the application once the management tasks have been completed.
  • Affects: 6.0.0-6.0.35 Moderate: DIGEST authentication weakness CVE-2012-3439 Three weaknesses in Tomcat's implementation of DIGEST authentication were identified and resolved: Tomcat tracked client rather than server nonces and nonce count.

Apache Tomcat 6.0 32 Error Report

Apache Tomcat Security Vulnerabilities This was fixed in revision 1417891. Apache Tomcat Input Validation Security Bypass Vulnerability Affects: OpenSSL 1.0.1-1.0.1f, tcnative 1.1.24-1.1.29

The second and third issues were discovered by the Tomcat security team during the resulting code review. This issue was first announced on 7 April 2014. For Oracle JRE that is known to be 6u22 or later. Tomcat 8 Vulnerabilities

Add a new filter, org.apache.catalina.filters.CsrfPreventionFilter, to provide generic cross-site request forgery (CSRF) protection for web applications.

Affects: 6.0.0-6.0.16 Important: Information disclosure CVE-2008-2370 When using a RequestDispatcher the target path was normalised before the query string was removed. Apache Tomcat 6.0.32 Vulnerabilities Therefore, although users must download 6.0.28 to obtain a version that includes a fix for this issue, version 6.0.27 is not included in the list of affected versions.

Prevent user passwords appearing in log files if a runtime exception (e.g.

These inefficiencies could allow an attacker, via a specially crafted request, to cause large amounts of CPU to be used which in turn could create a denial of service. Important: Denial of Service CVE-2014-0075 It was possible to craft a malformed chunk size as part of a chucked request that enabled an unlimited amount of data to be streamed to

Therefore, although users must download 6.0.18 to obtain a version that includes fixes for these issues, 6.0.17 is not included in the list of affected versions. Affects: 6.0.0-6.0.39 Low: Information Disclosure CVE-2014-0119 In limited circumstances it was possible for a malicious web application to replace the XML parsers used by Tomcat to process XSLTs for the default

The issue also occurred at the root of a web application in which case the presence of the web application was confirmed, even if a user did not have access.

Yes, of course I'm an adult! Based on a suggestion from adinamita. (kkolinko) 54527: Synchronize conf/web.xml mime mapping with Tomcat 7. (markt) Coyote 54248: Ensure that byte order marks are swallowed when using a Reader to read An explanation of how to deterine whether you are vulnerable and what steps to take, see the Tomcat Wiki's Heartbleed page. Patch provided by Jeremy Norris. (kkolinko) 51348: Fix possible NPE when processing WebDAV locks. (markt) Add a container event that is fired when a session's ID is changed, e.g.

Affects: 6.0.0-6.0.15 Important: Information disclosure CVE-2008-0002 If an exception occurs during the processing of parameters (eg if the client disconnects) then it is possible that the parameters submitted for that request Sachin Kumar R Gundi Greenhorn Posts: 4 I like...