| <!DOCTYPE html SYSTEM "about:legacy-compat"> |
| <html lang="en"><head><META http-equiv="Content-Type" content="text/html; charset=UTF-8"><meta name="viewport" content="width=device-width, initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" type="text/css"><title>Apache Tomcat® - Apache Tomcat 5 vulnerabilities</title><meta name="author" content="Apache Tomcat Project"><script src="https://www.apachecon.com/event-images/snippet.js"></script></head><body><div id="wrapper"><header id="header"><div class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div class="hamburger"></div></div><a href="http://tomcat.apache.org/"><img class="tomcat-logo pull-left noPrint" alt="Tomcat Home" src="res/images/tomcat.png"></a><h1 class="pull-left">Apache Tomcat<sup>®</sup></h1><div class="asf-logos pull-right"><a href="https://www.apache.org/foundation/contributing.html" target="_blank" class="pull-left"><img src="https://www.apache.org/images/SupportApache-small.png" class="support-asf" alt="Support Apache"></a><a href="http://www.apache.org/" target="_blank" class="pull-left"><img src="res/images/asf_logo_wide.svg" class="asf-logo" alt="The Apache Software Foundation"></a></div></div></header><main id="middle"><div><div id="mainLeft"><div id="nav-wrapper"><form action="https://www.google.com/search" method="get"><div class="searchbox"><input value="tomcat.apache.org" name="sitesearch" type="hidden"><input aria-label="Search text" placeholder="Search…" required="required" name="q" id="query" type="search"><button>GO</button></div></form><div class="asfevents"><a class="acevent" data-format="square" data-width="150"></a></div><nav><div><h2>Apache Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a href="./whichversion.html">Which version?</a></li><li><a href="https://tomcat.apache.org/download-11.cgi">Tomcat 11</a></li><li><a href="https://tomcat.apache.org/download-10.cgi">Tomcat 10</a></li><li><a href="https://tomcat.apache.org/download-90.cgi">Tomcat 9</a></li><li><a href="https://tomcat.apache.org/download-migration.cgi">Tomcat Migration Tool for Jakarta EE</a></li><li><a href="https://tomcat.apache.org/download-connectors.cgi">Tomcat Connectors</a></li><li><a href="https://tomcat.apache.org/download-native.cgi">Tomcat Native</a></li><li><a href="https://tomcat.apache.org/download-taglibs.cgi">Taglibs</a></li><li><a href="https://archive.apache.org/dist/tomcat/">Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a href="./tomcat-11.0-doc/index.html">Tomcat 11.0</a></li><li><a href="./tomcat-10.1-doc/index.html">Tomcat 10.1</a></li><li><a href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a href="./upgrading.html">Upgrading</a></li><li><a href="./connectors-doc/index.html">Tomcat Connectors</a></li><li><a href="./native-doc/index.html">Tomcat Native 2</a></li><li><a href="./native-1.3-doc/index.html">Tomcat Native 1.3</a></li><li><a href="https://cwiki.apache.org/confluence/display/TOMCAT">Wiki</a></li><li><a href="./migration.html">Migration Guide</a></li><li><a href="./presentations.html">Presentations</a></li><li><a href="https://cwiki.apache.org/confluence/x/Bi8lBg">Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a href="./security.html">Security Reports</a></li><li><a href="./findhelp.html">Find help</a></li><li><a href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ">FAQ</a></li><li><a href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug Database</a></li></ul></div><div><h2>Get Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a href="./source.html">Source code</a></li><li><a href="./ci.html">Buildbot</a></li><li><a href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a href="https://www.youtube.com/c/ApacheTomcatOfficial">YouTube</a></li></ul></div><div><h2>Misc</h2><ul><li><a href="./whoweare.html">Who We Are</a></li><li><a href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat">Swag</a></li><li><a href="./heritage.html">Heritage</a></li><li><a href="http://www.apache.org">Apache Home</a></li><li><a href="./resources.html">Resources</a></li><li><a href="./contact.html">Contact</a></li><li><a href="./legal.html">Legal</a></li><li><a href="https://privacy.apache.org/policies/privacy-policy-public.html">Privacy</a></li><li><a href="https://www.apache.org/foundation/contributing.html">Support Apache</a></li><li><a href="https://www.apache.org/foundation/sponsorship.html">Sponsorship</a></li><li><a href="http://www.apache.org/foundation/thanks.html">Thanks</a></li><li><a href="http://www.apache.org/licenses/">License</a></li></ul></div></nav></div></div><div id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 id="Apache_Tomcat_5.x_vulnerabilities">Apache Tomcat 5.x vulnerabilities</h3><div class="text"> |
| <p>This page lists all security vulnerabilities fixed in released versions |
| of Apache Tomcat<sup>®</sup> 5.x. Each vulnerability is given a |
| <a href="security-impact.html">security impact rating</a> by the Apache |
| Tomcat security team — please note that this rating may vary from |
| platform to platform. We also list the versions of Apache Tomcat the flaw |
| is known to affect, and where a flaw has not been verified list the |
| version with a question mark.</p> |
| |
| <p><strong>Note:</strong> Vulnerabilities that are not Tomcat vulnerabilities |
| but have either been incorrectly reported against Tomcat or where Tomcat |
| provides a workaround are listed at the end of this page.</p> |
| |
| <p><strong>Please note that Tomcat 5.0.x and 5.5.x are no longer supported. |
| Further vulnerabilities in the 5.0.x and 5.5.x branches will not be |
| fixed. Users should upgrade to 9.0.x or later to obtain security fixes. |
| Vulnerabilities fixed in Tomcat 5.5.26 onwards have not been assessed to |
| determine if they are present in the 5.0.x branch.</strong></p> |
| |
| <p>Please note that binary patches are never provided. If you need to |
| apply a source code patch, use the building instructions for the |
| Apache Tomcat version that you are using. For Tomcat 5.5 those are |
| <a href="/tomcat-5.5-doc/building.html"><code>building.html</code></a> |
| in documentation (<code>webapps/tomcat-docs</code> subdirectory of |
| a binary distributive) and <code>BUILDING.txt</code> file in a source |
| distributive.</p> |
| |
| <p>If you need help on building or configuring Tomcat or other help on |
| following the instructions to mitigate the known vulnerabilities listed |
| here, please send your questions to the public |
| <a href="lists.html">Tomcat Users mailing list</a> |
| </p> |
| |
| <p>If you have encountered an unlisted security vulnerability or other |
| unexpected behaviour that has <a href="security-impact.html">security |
| impact</a>, or if the descriptions here are incomplete, |
| please report them privately to the |
| <a href="security.html">Tomcat Security Team</a>. Thank you. |
| </p> |
| |
| </div><h3 id="Table_of_Contents">Table of Contents</h3><div class="text"> |
| <ul><li><a href="#Fixed_in_Apache_Tomcat_5.5.36">Fixed in Apache Tomcat 5.5.36</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.35">Fixed in Apache Tomcat 5.5.35</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.34">Fixed in Apache Tomcat 5.5.34</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.32">Fixed in Apache Tomcat 5.5.32</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.30">Fixed in Apache Tomcat 5.5.30</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.29">Fixed in Apache Tomcat 5.5.29</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.28">Fixed in Apache Tomcat 5.5.28</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.27">Fixed in Apache Tomcat 5.5.27</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.26">Fixed in Apache Tomcat 5.5.26</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.25,_5.0.SVN">Fixed in Apache Tomcat 5.5.25, 5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.24,_5.0.SVN">Fixed in Apache Tomcat 5.5.24, 5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.23,_5.0.SVN">Fixed in Apache Tomcat 5.5.23, 5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.22,_5.0.SVN">Fixed in Apache Tomcat 5.5.22, 5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.21,_5.0.SVN">Fixed in Apache Tomcat 5.5.21, 5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.21">Fixed in Apache Tomcat 5.5.21</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.18,_5.0.SVN">Fixed in Apache Tomcat 5.5.18, 5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.17,_5.0.SVN">Fixed in Apache Tomcat 5.5.17, 5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.16,_5.0.SVN">Fixed in Apache Tomcat 5.5.16, 5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.13,_5.0.SVN">Fixed in Apache Tomcat 5.5.13, 5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.7,_5.0.SVN">Fixed in Apache Tomcat 5.5.7, 5.0.SVN</a></li><li><a href="#Fixed_in_Apache_Tomcat_5.5.1">Fixed in Apache Tomcat 5.5.1</a></li><li><a href="#Not_a_vulnerability_in_Tomcat">Not a vulnerability in Tomcat</a></li></ul> |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.36"><span class="pull-right">released 10 Oct 2012</span> Fixed in Apache Tomcat 5.5.36</h3><div class="text"> |
| |
| <p><strong>Moderate: DIGEST authentication weakness</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3439" rel="nofollow">CVE-2012-3439</a></p> |
| |
| <p>Three weaknesses in Tomcat's implementation of DIGEST authentication |
| were identified and resolved: |
| </p> |
| <ol> |
| <li>Tomcat tracked client rather than server nonces and nonce count.</li> |
| <li>When a session ID was present, authentication was bypassed.</li> |
| <li>The user name and password were not checked before when indicating |
| that a nonce was stale.</li> |
| </ol> |
| <p> |
| These issues reduced the security of DIGEST authentication making |
| replay attacks possible in some circumstances. |
| </p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1392248">1392248</a>.</p> |
| |
| <p>The first issue was reported by Tilmann Kuhn to the Tomcat security team |
| on 19 July 2012. The second and third issues were discovered by the |
| Tomcat security team during the resulting code review. All three issues |
| were made public on 5 November 2012.</p> |
| |
| <p>Affects: 5.5.0-5.5.35</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.35"><span class="pull-right">released 16 Jan 2012</span> Fixed in Apache Tomcat 5.5.35</h3><div class="text"> |
| |
| <p><strong>Important: Denial of service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0022" rel="nofollow">CVE-2012-0022</a></p> |
| |
| <p>Analysis of the recent hash collision vulnerability identified unrelated |
| inefficiencies with Apache Tomcat's handling of large numbers of |
| parameters and parameter values. These inefficiencies could allow an |
| attacker, via a specially crafted request, to cause large amounts of CPU |
| to be used which in turn could create a denial of service. The issue was |
| addressed by modifying the Tomcat parameter handling code to efficiently |
| process large numbers of parameters and parameter values.</p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1221282">1221282</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1224640">1224640</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1228191">1228191</a>.</p> |
| |
| <p>This was identified by the Tomcat security team on 21 October 2011 and |
| made public on 17 January 2012.</p> |
| |
| <p>Affects: 5.5.0-5.5.34</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.34"><span class="pull-right">released 22 Sep 2011</span> Fixed in Apache Tomcat 5.5.34</h3><div class="text"> |
| |
| <p><strong>Moderate: Multiple weaknesses in HTTP DIGEST authentication</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1184" rel="nofollow">CVE-2011-1184</a></p> |
| |
| <p>Note: Mitre elected to break this issue down into multiple issues and |
| have allocated the following additional references to parts of this |
| issue: |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5062" rel="nofollow">CVE-2011-5062</a>, |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5063" rel="nofollow">CVE-2011-5063</a> and |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5064" rel="nofollow">CVE-2011-5064</a>. The Apache Tomcat security team will |
| continue to treat this as a single issue using the reference |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1184" rel="nofollow">CVE-2011-1184</a>.</p> |
| |
| <p>The implementation of HTTP DIGEST authentication was discovered to have |
| several weaknesses:</p> |
| <ul> |
| <li>replay attacks were permitted</li> |
| <li>server nonces were not checked</li> |
| <li>client nonce counts were not checked</li> |
| <li>qop values were not checked</li> |
| <li>realm values were not checked</li> |
| <li>the server secret was hard-coded to a known string</li> |
| </ul> |
| <p> |
| The result of these weaknesses is that DIGEST authentication was only as |
| secure as BASIC authentication. |
| </p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1159309">revision 1159309</a>.</p> |
| |
| <p>This was identified by the Tomcat security team on 16 March 2011 and |
| made public on 26 September 2011.</p> |
| |
| <p>Affects: 5.5.0-5.5.33</p> |
| |
| <p><strong>Low: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2204" rel="nofollow">CVE-2011-2204</a></p> |
| |
| <p>When using the MemoryUserDatabase (based on tomcat-users.xml) and |
| creating users via JMX, an exception during the user creation process may |
| trigger an error message in the JMX client that includes the user's |
| password. This error message is also written to the Tomcat logs. User |
| passwords are visible to administrators with JMX access and/or |
| administrators with read access to the tomcat-users.xml file. Users that |
| do not have these permissions but are able to read log files may be able |
| to discover a user's password.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1140072">revision 1140072</a>.</p> |
| |
| <p>This was identified by Polina Genova on 14 June 2011 and |
| made public on 27 June 2011.</p> |
| |
| <p>Affects: 5.5.0-5.5.33</p> |
| |
| <p><strong>Low: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2526" rel="nofollow">CVE-2011-2526</a></p> |
| |
| <p>Tomcat provides support for sendfile with the HTTP APR |
| connector. sendfile is used automatically for content served via the |
| DefaultServlet and deployed web applications may use it directly via |
| setting request attributes. These request attributes were not validated. |
| When running under a security manager, this lack of validation allowed a |
| malicious web application to do one or more of the following that would |
| normally be prevented by a security manager: |
| </p> |
| <ul> |
| <li>return files to users that the security manager should make |
| inaccessible</li> |
| <li>terminate (via a crash) the JVM</li> |
| </ul> |
| <p>Additionally, these vulnerabilities only occur when all of the following |
| are true:</p> |
| <ul> |
| <li>untrusted web applications are being used</li> |
| <li>the SecurityManager is used to limit the untrusted web applications |
| </li> |
| <li>the HTTP APR connector is used</li> |
| <li>sendfile is enabled for the connector (this is the default)</li> |
| </ul> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1158244">revision 1158244</a>.</p> |
| |
| <p>This was identified by the Tomcat security team on 7 July 2011 and |
| made public on 13 July 2011.</p> |
| |
| <p>Affects: 5.5.0-5.5.33</p> |
| |
| <p><strong>Important: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2729" rel="nofollow">CVE-2011-2729</a></p> |
| |
| <p>Due to a bug in the capabilities code, jsvc (the service wrapper for |
| Linux that is part of the Commons Daemon project) does not drop |
| capabilities allowing the application to access files and directories |
| owned by superuser. This vulnerability only occurs when all of the |
| following are true: |
| </p> |
| <ul> |
| <li>Tomcat is running on a Linux operating system</li> |
| <li>jsvc was compiled with libcap</li> |
| <li>-user parameter is used</li> |
| </ul> |
| <p> |
| Affected Tomcat versions shipped with source files for jsvc that included |
| this vulnerability. |
| </p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1159346">revision 1159346</a>.</p> |
| |
| <p>This was identified by Wilfried Weissmann on 20 July 2011 and made public |
| on 12 August 2011.</p> |
| |
| <p>Affects: 5.5.32-5.5.33</p> |
| |
| <p><strong>Important: Authentication bypass and information disclosure |
| </strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3190" rel="nofollow">CVE-2011-3190</a></p> |
| |
| <p>Apache Tomcat supports the AJP protocol which is used with reverse |
| proxies to pass requests and associated data about the request from the |
| reverse proxy to Tomcat. The AJP protocol is designed so that when a |
| request includes a request body, an unsolicited AJP message is sent to |
| Tomcat that includes the first part (or possibly all) of the request |
| body. In certain circumstances, Tomcat did not process this message as a |
| request body but as a new request. This permitted an attacker to have |
| full control over the AJP message permitting authentication bypass and |
| information disclosure. This vulnerability only occurs when all of the |
| following are true: |
| </p> |
| <ul> |
| <li>The org.apache.jk.server.JkCoyoteHandler AJP connector is not used |
| </li> |
| <li>POST requests are accepted</li> |
| <li>The request body is not processed</li> |
| </ul> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1162960">revision 1162960</a>.</p> |
| |
| <p>This was reported publicly on 20th August 2011.</p> |
| |
| <p>Affects: 5.5.0-5.5.33</p> |
| |
| <p>Mitigation options:</p> |
| <ul> |
| <li>Upgrade to Tomcat 5.5.34.</li> |
| <li>Apply the appropriate <a href="https://svn.apache.org/viewvc?view=rev&rev=1162960">patch</a>.</li> |
| <li>Configure both Tomcat and the reverse proxy to use a shared secret.<br> |
| (It is "<code>request.secret</code>" attribute in AJP <Connector>, |
| "<code>worker.<i>workername</i>.secret</code>" directive for mod_jk. |
| The mod_proxy_ajp module currently does not support shared secrets). |
| </li> |
| <li>Use the org.apache.jk.server.JkCoyoteHandler (BIO) AJP connector |
| implementation.<br> |
| (It is automatically selected if you do not have Tomcat-Native library |
| installed. It can be also selected explicitly: |
| <code><Connector protocol="org.apache.jk.server.JkCoyoteHandler"></code>). |
| </li> |
| </ul> |
| |
| <p>References:</p> |
| <ul> |
| <li><a href="/tomcat-5.5-doc/config/ajp.html">AJP Connector documentation (Tomcat 5.5)</a></li> |
| <li><a href="/connectors-doc/reference/workers.html">workers.properties configuration (mod_jk)</a></li> |
| </ul> |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.32"><span class="pull-right">released 1 Feb 2011</span> Fixed in Apache Tomcat 5.5.32</h3><div class="text"> |
| |
| <p><strong>Low: Cross-site scripting</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0013" rel="nofollow">CVE-2011-0013</a></p> |
| |
| <p>The HTML Manager interface displayed web application provided data, such |
| as display names, without filtering. A malicious web application could |
| trigger script execution by an administrative user when viewing the |
| manager pages.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1057518">revision 1057518</a>.</p> |
| |
| <p>This was identified by the Tomcat security team on 12 Nov 2010 and |
| made public on 5 Feb 2011.</p> |
| |
| <p>Affects: 5.5.0-5.5.31</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.30"><span class="pull-right">released 9 Jul 2010</span> Fixed in Apache Tomcat 5.5.30</h3><div class="text"> |
| |
| <p><strong>Low: SecurityManager file permission bypass</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3718" rel="nofollow">CVE-2010-3718</a></p> |
| |
| <p>When running under a SecurityManager, access to the file system is |
| limited but web applications are granted read/write permissions to the |
| work directory. This directory is used for a variety of temporary files |
| such as the intermediate files generated when compiling JSPs to Servlets. |
| The location of the work directory is specified by a ServletContect |
| attribute that is meant to be read-only to web applications. However, |
| due to a coding error, the read-only setting was not applied. Therefore, |
| a malicious web application may modify the attribute before Tomcat |
| applies the file permissions. This can be used to grant read/write |
| permissions to any area on the file system which a malicious web |
| application may then take advantage of. This vulnerability is only |
| applicable when hosting web applications from untrusted sources such as |
| shared hosting environments.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1027610">revision 1027610</a>.</p> |
| |
| <p>This was discovered by the Tomcat security team on 12 Oct 2010 and |
| made public on 5 Feb 2011.</p> |
| |
| <p>Affects: 5.5.0-5.5.29</p> |
| |
| <p><strong>Important: Remote Denial Of Service and Information Disclosure |
| Vulnerability</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2227" rel="nofollow">CVE-2010-2227</a></p> |
| |
| <p>Several flaws in the handling of the 'Transfer-Encoding' header were |
| found that prevented the recycling of a buffer. A remote attacker could |
| trigger this flaw which would cause subsequent requests to fail and/or |
| information to leak between requests. This flaw is mitigated if Tomcat is |
| behind a reverse proxy (such as Apache httpd 2.2) as the proxy should |
| reject the invalid transfer encoding header.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=959428">revision 959428</a>.</p> |
| |
| <p>This was first reported to the Tomcat security team on 14 Jun 2010 and |
| made public on 9 Jul 2010.</p> |
| |
| <p>Affects: 5.5.0-5.5.29</p> |
| |
| <p><strong>Low: Information disclosure in authentication headers</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1157" rel="nofollow">CVE-2010-1157</a></p> |
| |
| <p>The <code>WWW-Authenticate</code> HTTP header for BASIC and DIGEST |
| authentication includes a realm name. If a |
| <code><realm-name></code> element is specified for the application |
| in web.xml it will be used. However, a <code><realm-name></code> |
| is not specified then Tomcat will generate realm name using the code |
| snippet <code>request.getServerName() + ":" + |
| request.getServerPort()</code>. In some circumstances this can expose |
| the local host name or IP address of the machine running Tomcat. |
| </p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=936541">revision 936541</a>.</p> |
| |
| <p>This was first reported to the Tomcat security team on 31 Dec 2009 and |
| made public on 21 Apr 2010.</p> |
| |
| <p>Affects: 5.5.0-5.5.29</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.29"><span class="pull-right">released 20 Apr 2010</span> Fixed in Apache Tomcat 5.5.29</h3><div class="text"> |
| |
| <p><strong>Low: Arbitrary file deletion and/or alteration on deploy</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2693" rel="nofollow">CVE-2009-2693</a></p> |
| |
| <p>When deploying WAR files, the WAR files were not checked for directory |
| traversal attempts. This allows an attacker to create arbitrary content |
| outside of the web root by including entries such as |
| <code>../../bin/catalina.sh</code> in the WAR.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=902650">revision 902650</a>.</p> |
| |
| <p>This was first reported to the Tomcat security team on 30 Jul 2009 and |
| made public on 1 Mar 2010.</p> |
| |
| <p>Affects: 5.5.0-5.5.28</p> |
| |
| <p><strong>Low: Insecure partial deploy after failed undeploy</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2901" rel="nofollow">CVE-2009-2901</a></p> |
| |
| <p>By default, Tomcat automatically deploys any directories placed in a |
| host's appBase. This behaviour is controlled by the autoDeploy attribute |
| of a host which defaults to true. After a failed undeploy, the remaining |
| files will be deployed as a result of the autodeployment process. |
| Depending on circumstances, files normally protected by one or more |
| security constraints may be deployed without those security constraints, |
| making them accessible without authentication. This issue only affects |
| Windows platforms</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=902650">revision 902650</a>.</p> |
| |
| <p>This was first reported to the Tomcat security team on 30 Jul 2009 and |
| made public on 1 Mar 2010.</p> |
| |
| <p>Affects: 5.5.0-5.5.28 (Windows only)</p> |
| |
| <p><strong>Low: Unexpected file deletion in work directory</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2902" rel="nofollow">CVE-2009-2902</a></p> |
| |
| <p>When deploying WAR files, the WAR file names were not checked for |
| directory traversal attempts. For example, deploying and undeploying |
| <code>...war</code> allows an attacker to cause the deletion of the |
| current contents of the host's work directory which may cause problems |
| for currently running applications.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=902650">revision 902650</a>.</p> |
| |
| <p>This was first reported to the Tomcat security team on 30 Jul 2009 and |
| made public on 1 Mar 2010.</p> |
| |
| <p>Affects: 5.5.0-5.5.28</p> |
| |
| <p><strong>Low: Insecure default password</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3548" rel="nofollow">CVE-2009-3548</a></p> |
| |
| <p>The Windows installer defaults to a blank password for the administrative |
| user. If this is not changed during the install process, then by default |
| a user is created with the name admin, roles admin and manager and a |
| blank password.</p> |
| |
| <p>Affects: 5.5.0-5.5.28</p> |
| |
| <p>This was first reported to the Tomcat security team on 26 Oct 2009 and |
| made public on 9 Nov 2009.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=919006">revision 919006</a>.</p> |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.28"><span class="pull-right">released 4 Sep 2009</span> Fixed in Apache Tomcat 5.5.28</h3><div class="text"> |
| <p><strong>Important: Information Disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5515" rel="nofollow">CVE-2008-5515</a></p> |
| |
| <p>When using a RequestDispatcher obtained from the Request, the target path |
| was normalised before the query string was removed. A request that |
| included a specially crafted request parameter could be used to access |
| content that would otherwise be protected by a security constraint or by |
| locating it in under the WEB-INF directory.</p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=782757">782757</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=783291">783291</a>.</p> |
| |
| <p>This was first reported to the Tomcat security team on 11 Dec 2008 and |
| made public on 8 Jun 2009.</p> |
| |
| <p>Affects: 5.5.0-5.5.27</p> |
| |
| <p><strong>Important: Denial of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0033" rel="nofollow">CVE-2009-0033</a></p> |
| |
| <p>If Tomcat receives a request with invalid headers via the Java AJP |
| connector, it does not return an error and instead closes the AJP |
| connection. In case this connector is member of a mod_jk load balancing |
| worker, this member will be put into an error state and will be blocked |
| from use for approximately one minute. Thus the behaviour can be used for |
| a denial of service attack using a carefully crafted request.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=781362">revision 781362</a>.</p> |
| |
| <p>This was first reported to the Tomcat security team on 26 Jan 2009 and |
| made public on 3 Jun 2009.</p> |
| |
| <p>Affects: 5.5.0-5.5.27</p> |
| |
| <p><strong>Low: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0580" rel="nofollow">CVE-2009-0580</a></p> |
| |
| <p>Due to insufficient error checking in some authentication classes, Tomcat |
| allows for the enumeration (brute force testing) of user names by |
| supplying illegally URL encoded passwords. The attack is possible if FORM |
| based authentication (j_security_check) is used with the MemoryRealm. |
| Note that in early versions, the DataSourceRealm and JDBCRealm were also |
| affected.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=781379">revision 781379</a>.</p> |
| |
| <p>This was first reported to the Tomcat security team on 25 Feb 2009 and |
| made public on 3 Jun 2009.</p> |
| |
| <p>Affects: 5.5.0-5.5.27 (Memory Realm), 5.5.0-5.5.5 (DataSource and JDBC |
| Realms)</p> |
| |
| <p><strong>Low: Cross-site scripting</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0781" rel="nofollow">CVE-2009-0781</a></p> |
| |
| <p>The calendar application in the examples web application contains an |
| XSS flaw due to invalid HTML which renders the XSS filtering protection |
| ineffective.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=750928">revision 750928</a>.</p> |
| |
| <p>This was first reported to the Tomcat security team on 5 Mar 2009 and |
| made public on 6 Mar 2009.</p> |
| |
| <p>Affects: 5.5.0-5.5.27</p> |
| |
| <p><strong>Low: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0783" rel="nofollow">CVE-2009-0783</a></p> |
| |
| <p>Bugs <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=29936">29936</a> and <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=45933">45933</a> allowed a web application |
| to replace the XML parser used by |
| Tomcat to process web.xml, context.xml and tld files. In limited |
| circumstances these bugs may allow a rogue web application to view and/or |
| alter the web.xml, context.xml and tld files of other web applications |
| deployed on the Tomcat instance.</p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=681156">681156</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=781542">781542</a>.</p> |
| |
| <p>This was first reported to the Tomcat security team on 2 Mar 2009 and |
| made public on 4 Jun 2009.</p> |
| |
| <p>Affects: 5.5.0-5.5.27</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.27"><span class="pull-right">released 8 Sep 2008</span> Fixed in Apache Tomcat 5.5.27</h3><div class="text"> |
| <p><strong>Low: Cross-site scripting</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1232" rel="nofollow">CVE-2008-1232</a></p> |
| |
| <p>The message argument of HttpServletResponse.sendError() call is not only |
| displayed on the error page, but is also used for the reason-phrase of |
| HTTP response. This may include characters that are illegal in HTTP |
| headers. It is possible for a specially crafted message to result in |
| arbitrary content being injected into the HTTP response. For a successful |
| XSS attack, unfiltered user supplied data must be included in the message |
| argument.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=680947">revision 680947</a>.</p> |
| |
| <p>This was first reported to the Tomcat security team on 24 Jan 2008 and |
| made public on 1 Aug 2008.</p> |
| |
| <p>Affects: 5.5.0-5.5.26</p> |
| |
| <p><strong>Low: Cross-site scripting</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1947" rel="nofollow">CVE-2008-1947</a></p> |
| |
| <p>The Host Manager web application did not escape user provided data before |
| including it in the output. This enabled a XSS attack. This application |
| now filters the data before use. This issue may be mitigated by logging |
| out (closing the browser) of the application once the management tasks |
| have been completed.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=662583">revision 662583</a>.</p> |
| |
| <p>This was first reported to the Tomcat security team on 15 May 2008 and |
| made public on 28 May 2008.</p> |
| |
| <p>Affects: 5.5.9-5.5.26</p> |
| |
| <p><strong>Important: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2370" rel="nofollow">CVE-2008-2370</a></p> |
| |
| <p>When using a RequestDispatcher the target path was normalised before the |
| query string was removed. A request that included a specially crafted |
| request parameter could be used to access content that would otherwise be |
| protected by a security constraint or by locating it in under the WEB-INF |
| directory.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=680949">revision 680949</a>.</p> |
| |
| <p>This was first reported to the Tomcat security team on 13 Jun 2008 and |
| made public on 1 August 2008.</p> |
| |
| <p>Affects: 5.5.0-5.5.26</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.26"><span class="pull-right">released 5 Feb 2008</span> Fixed in Apache Tomcat 5.5.26</h3><div class="text"> |
| <p><strong>Low: Session hi-jacking</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5333" rel="nofollow">CVE-2007-5333</a></p> |
| |
| <p>The previous fix for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3385" rel="nofollow">CVE-2007-3385</a> was incomplete. It did |
| not consider the use of quotes or %5C within a cookie value.</p> |
| |
| <p>Affects: 5.5.0-5.5.25</p> |
| |
| <p><strong>Low: Elevated privileges</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5342" rel="nofollow">CVE-2007-5342</a></p> |
| |
| <p>The JULI logging component allows web applications to provide their own |
| logging configurations. The default security policy does not restrict |
| this configuration and allows an untrusted web application to add files |
| or overwrite existing files where the Tomcat process has the necessary |
| file permissions to do so.</p> |
| |
| <p>Affects: 5.5.9-5.5.25</p> |
| |
| <p><strong>Important: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5461" rel="nofollow">CVE-2007-5461</a></p> |
| |
| <p>When Tomcat's WebDAV servlet is configured for use with a context and |
| has been enabled for write, some WebDAV requests that specify an entity |
| with a SYSTEM tag can result in the contents of arbitary files being |
| returned to the client.</p> |
| |
| <p>Affects: 5.5.0-5.5.25</p> |
| |
| <p><strong>Important: Data integrity</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6286" rel="nofollow">CVE-2007-6286</a></p> |
| |
| <p>When using the native (APR based) connector, connecting to the SSL port |
| using netcat and then disconnecting without sending any data will cause |
| tomcat to handle a duplicate copy of one of the recent requests.</p> |
| |
| <p>Affects: 5.5.11-5.5.25</p> |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.25,_5.0.SVN"><span class="pull-right">released 8 Sep 2007</span> Fixed in Apache Tomcat 5.5.25, 5.0.SVN</h3><div class="text"> |
| <p><strong>Low: Cross-site scripting</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2449" rel="nofollow">CVE-2007-2449</a></p> |
| |
| <p>JSPs within the examples web application did not escape user provided |
| data before including it in the output. This enabled a XSS attack. These |
| JSPs now filter the data before use. This issue may be mitigated by |
| undeploying the examples web application. Note that it is recommended |
| that the examples web application is not installed on a production |
| system. |
| </p> |
| |
| <p>Affects: 5.0.0-5.0.30, 5.5.0-5.5.24</p> |
| |
| <p><strong>Low: Cross-site scripting</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2450" rel="nofollow">CVE-2007-2450</a></p> |
| |
| <p>The Manager and Host Manager web applications did not escape user |
| provided data before including it in the output. This enabled a XSS |
| attack. These applications now filter the data before use. This issue may |
| be mitigated by logging out (closing the browser) of the application once |
| the management tasks have been completed.</p> |
| |
| <p>Affects: 5.0.0-5.0.30, 5.5.0-5.5.24</p> |
| |
| <p><strong>Low: Session hi-jacking</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3382" rel="nofollow">CVE-2007-3382</a></p> |
| |
| <p>Tomcat incorrectly treated a single quote character (') in a cookie |
| value as a delimiter. In some circumstances this lead to the leaking of |
| information such as session ID to an attacker.</p> |
| |
| <p>Affects: 5.0.0-5.0.30, 5.5.0-5.5.24</p> |
| |
| <p><strong>Low: Session hi-jacking</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3385" rel="nofollow">CVE-2007-3385</a></p> |
| |
| <p>Tomcat incorrectly handled the character sequence \" in a cookie value. |
| In some circumstances this lead to the leaking of information such as |
| session ID to an attacker.</p> |
| |
| <p>Affects: 5.0.0-5.0.30, 5.5.0-5.5.24</p> |
| |
| <p><strong>Low: Cross-site scripting</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3386" rel="nofollow">CVE-2007-3386</a></p> |
| |
| <p>The Host Manager Servlet did not filter user supplied data before |
| display. This enabled an XSS attack.</p> |
| |
| <p>Affects: 5.5.0-5.5.24</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.24,_5.0.SVN"><span class="pull-right">Not released</span> Fixed in Apache Tomcat 5.5.24, 5.0.SVN</h3><div class="text"> |
| <p><strong>Moderate: Cross-site scripting</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1355" rel="nofollow">CVE-2007-1355</a></p> |
| |
| <p>The JSP and Servlet included in the sample application within the Tomcat |
| documentation webapp did not escape user provided data before including |
| it in the output. This enabled a XSS attack. These pages have been |
| simplified not to use any user provided data in the output.</p> |
| |
| <p>Affects: 5.0.0-5.0.30, 5.5.0-5.5.23</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.23,_5.0.SVN"><span class="pull-right">released 9 Mar 2007</span> Fixed in Apache Tomcat 5.5.23, 5.0.SVN</h3><div class="text"> |
| <p><strong>Important: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2090" rel="nofollow">CVE-2005-2090</a></p> |
| |
| <p>Requests with multiple content-length headers should be rejected as |
| invalid. When multiple components (firewalls, caches, proxies and Tomcat) |
| process a sequence of requests where one or more requests contain |
| multiple content-length headers and several components do not |
| reject the request and make different decisions as to which |
| content-length header to use an attacker can poison a web-cache, perform |
| an XSS attack and obtain sensitive information from requests other then |
| their own. Tomcat now returns 400 for requests with multiple |
| content-length headers. |
| </p> |
| |
| <p>Affects: 5.0.0-5.0.30, 5.5.0-5.5.22</p> |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.22,_5.0.SVN"><span class="pull-right">not released</span> Fixed in Apache Tomcat 5.5.22, 5.0.SVN</h3><div class="text"> |
| <p><strong>Important: Directory traversal</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0450" rel="nofollow">CVE-2007-0450</a></p> |
| |
| <p>The fix for this issue was insufficient. A fix was also required in the |
| JK connector module for httpd. See <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1860" rel="nofollow">CVE-2007-1860</a> for further |
| information.</p> |
| |
| <p>Tomcat permits '\', '%2F' and '%5C' as path delimiters. When Tomcat is used |
| behind a proxy (including, but not limited to, Apache HTTP server with |
| mod_proxy and mod_jk) configured to only proxy some contexts, a HTTP request |
| containing strings like "/\../" may allow attackers to work around the context |
| restriction of the proxy, and access the non-proxied contexts. |
| </p> |
| |
| <p>The following Java system properties have been added to Tomcat to provide |
| additional control of the handling of path delimiters in URLs (both options |
| default to false): |
| </p> |
| <ul> |
| <li> |
| <code>org.apache.tomcat.util.buf.UDecoder.ALLOW_ENCODED_SLASH</code>: <code>true|false</code> |
| </li> |
| <li> |
| <code>org.apache.catalina.connector.CoyoteAdapter.ALLOW_BACKSLASH</code>: <code>true|false</code> |
| </li> |
| </ul> |
| |
| <p>Due to the impossibility to guarantee that all URLs are handled by Tomcat as |
| they are in proxy servers, Tomcat should always be secured as if no proxy |
| restricting context access was used. |
| </p> |
| |
| <p>Affects: 5.0.0-5.0.30, 5.5.0-5.5.21</p> |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.21,_5.0.SVN"><span class="pull-right">not released</span> Fixed in Apache Tomcat 5.5.21, 5.0.SVN</h3><div class="text"> |
| <p><strong>Low: Cross-site scripting</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1358" rel="nofollow">CVE-2007-1358</a></p> |
| |
| <p>Web pages that display the Accept-Language header value sent by the |
| client are susceptible to a cross-site scripting attack if they assume |
| the Accept-Language header value conforms to RFC 2616. Under normal |
| circumstances this would not be possible to exploit, however older |
| versions of Flash player were known to allow carefully crafted malicious |
| Flash files to make requests with such custom headers. When generating |
| the response for <code>getLocale()</code> and <code>getLocales()</code>, |
| Tomcat now ignores values for Accept-Language headers that do not conform |
| to RFC 2616. Applications that use the raw header values directly should |
| not assume that the headers conform to RFC 2616 and should filter the |
| values appropriately.</p> |
| |
| <p>Affects: 5.0.0-5.0.30, 5.5.0-5.5.20</p> |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.21"><span class="pull-right">not released</span> Fixed in Apache Tomcat 5.5.21</h3><div class="text"> |
| <p><strong>Moderate: Session hi-jacking</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0128" rel="nofollow">CVE-2008-0128</a></p> |
| |
| <p>When using the SingleSignOn Valve via https the Cookie JSESSIONIDSSO is |
| transmitted without the "secure" attribute, resulting in it being |
| transmitted to any content that is - by purpose or error - requested via |
| http from the same server. </p> |
| |
| <p>Affects: 5.0.0-5.0.SVN, 5.5.0-5.5.20</p> |
| |
| <p><strong>Low: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4308" rel="nofollow">CVE-2008-4308</a></p> |
| |
| <p><a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=40771">Bug |
| 40771</a> may result in the disclosure of POSTed content from a previous |
| request. For a vulnerability to exist, the content read from the input |
| stream must be disclosed, eg via writing it to the response and committing |
| the response, before the ArrayIndexOutOfBoundsException occurs which will |
| halt processing of the request.</p> |
| |
| <p>Affects: 5.5.10-5.5.20 (5.0.x unknown)</p> |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.18,_5.0.SVN"><span class="pull-right">not released</span> Fixed in Apache Tomcat 5.5.18, 5.0.SVN</h3><div class="text"> |
| <p><strong>Moderate: Cross-site scripting</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7195" rel="nofollow">CVE-2006-7195</a></p> |
| |
| <p>The implicit-objects.jsp in the examples webapp displayed a number of |
| unfiltered header values. This enabled a XSS attack. These values are now |
| filtered.</p> |
| |
| <p>Affects: 5.0.0-5.0.30, 5.5.0-5.5.17</p> |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.17,_5.0.SVN"><span class="pull-right">released 27 Apr 2006</span> Fixed in Apache Tomcat 5.5.17, 5.0.SVN</h3><div class="text"> |
| <p><strong>Important: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1858" rel="nofollow">CVE-2007-1858</a></p> |
| |
| <p>The default SSL configuration permitted the use of insecure cipher suites |
| including the anonymous cipher suite. The default configuration no |
| longer permits the use of insecure cipher suites.</p> |
| |
| <p>Affects: 5.0.0-5.0.30, 5.5.0-5.5.16</p> |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.16,_5.0.SVN"><span class="pull-right">released 15 Mar 2006</span> Fixed in Apache Tomcat 5.5.16, 5.0.SVN</h3><div class="text"> |
| <p><strong>Low: Cross-site scripting</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7196" rel="nofollow">CVE-2006-7196</a></p> |
| |
| <p>The calendar application included as part of the JSP examples is |
| susceptible to a cross-site scripting attack as it does not escape |
| user provided data before including it in the returned page.</p> |
| |
| <p>Affects: 5.0.0-5.0.30, 5.5.0-5.5.15</p> |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.13,_5.0.SVN">Fixed in Apache Tomcat 5.5.13, 5.0.SVN</h3><div class="text"> |
| <p><strong>Low: Directory listing</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3835" rel="nofollow">CVE-2006-3835</a></p> |
| |
| <p>This is expected behaviour when directory listings are enabled. The |
| semicolon (;) is the separator for path parameters so inserting one |
| before a file name changes the request into a request for a directory |
| with a path parameter. If directory listings are enabled, a directory |
| listing will be shown. In response to this and other directory listing |
| issues, directory listings were changed to be disabled by default.</p> |
| |
| <p>Affects: 5.0.0-5.0.30, 5.5.0-5.5.12</p> |
| |
| <p><strong>Important: Denial of service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3510" rel="nofollow">CVE-2005-3510</a></p> |
| |
| <p>The root cause is the relatively expensive calls required to generate |
| the content for the directory listings. If directory listings are |
| enabled, the number of files in each directory should be kept to a |
| minimum. In response to this issue, directory listings were changed to |
| be disabled by default. Additionally, a |
| <a href="http://marc.info/?l=tomcat-dev&m=113356822719767&w=2"> |
| patch</a> has been proposed that would improve performance, particularly |
| for large directories, by caching directory listings.</p> |
| |
| <p>Affects: 5.0.0-5.0.30, 5.5.0-5.5.12</p> |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.7,_5.0.SVN">Fixed in Apache Tomcat 5.5.7, 5.0.SVN</h3><div class="text"> |
| <p><strong>Low: Cross-site scripting</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4838" rel="nofollow">CVE-2005-4838</a></p> |
| |
| <p>Various JSPs included as part of the JSP examples and the Tomcat Manager |
| are susceptible to a cross-site scripting attack as they do not escape |
| user provided data before including it in the returned page.</p> |
| |
| <p>Affects: 5.0.0-5.0.30, 5.5.0-5.5.6</p> |
| </div><h3 id="Fixed_in_Apache_Tomcat_5.5.1">Fixed in Apache Tomcat 5.5.1</h3><div class="text"> |
| <p><strong>Low: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3271" rel="nofollow">CVE-2008-3271</a></p> |
| |
| <p><a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=25835"> |
| Bug 25835</a> can, in rare circumstances - this has only been reproduced |
| using a debugger to force a particular processing sequence for two threads - |
| allow a user from a non-permitted IP address to gain access to a context |
| that is protected with a valve that extends RequestFilterValve. This includes |
| the standard RemoteAddrValve and RemoteHostValve implementations.</p> |
| |
| <p>Affects: 5.5.0 (5.0.x unknown)</p> |
| </div><h3 id="Not_a_vulnerability_in_Tomcat">Not a vulnerability in Tomcat</h3><div class="text"> |
| |
| <p><strong>Important: Remote Denial Of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4476" rel="nofollow">CVE-2010-4476</a></p> |
| |
| <p>A JVM bug could cause Double conversion to hang JVM when accessing to a |
| form based security constrained page or any page that calls |
| javax.servlet.ServletRequest.getLocale() or |
| javax.servlet.ServletRequest.getLocales(). A specially crafted request |
| can be used to trigger a denial of service. |
| </p> |
| |
| <p>A work-around for this JVM bug was provided in |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1066318">revision 1066318</a>. |
| This work-around is included in Tomcat 5.5.33 onwards.</p> |
| |
| <p>This was first reported to the Tomcat security team on 01 Feb 2011 and |
| made public on 31 Jan 2011.</p> |
| |
| <p>Affects: 5.5.0-5.5.32</p> |
| |
| <p><strong>Moderate: TLS SSL Man In The Middle</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555" rel="nofollow">CVE-2009-3555</a></p> |
| |
| <p>A vulnerability exists in the TLS protocol that allows an attacker to |
| inject arbitrary requests into an TLS stream during renegotiation.</p> |
| |
| <p>The TLS implementation used by Tomcat varies with connector. The blocking |
| IO (BIO) and non-blocking (NIO) connectors use the JSSE implementation |
| provided by the JVM. The APR/native connector uses OpenSSL.</p> |
| |
| <p>The BIO connector is vulnerable if the JSSE version used is vulnerable. |
| To workaround this until a fix is available in JSSE, a new connector |
| attribute <code>allowUnsafeLegacyRenegotiation</code> has been added to |
| the BIO connector. It should be set to <code>false</code> (the default) |
| to protect against this vulnerability.</p> |
| |
| <p>The NIO connector is not vulnerable as it does not support |
| renegotiation.</p> |
| |
| <p>The APR/native workarounds are detailed on the |
| <a href="security-native.html">APR/native connector security page</a>. |
| </p> |
| |
| <p>Users should be aware that the impact of disabling renegotiation will |
| vary with both application and client. In some circumstances disabling |
| renegotiation may result in some clients being unable to access the |
| application.</p> |
| |
| <p>A workaround was implemented in |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=904851">revision 904851</a> |
| that provided the new <code>allowUnsafeLegacyRenegotiation</code> |
| attribute. This work around is included in Tomcat 5.5.29 onwards.</p> |
| |
| <p>Support for the new TLS renegotiation protocol (RFC 5746) that does not |
| have this security issue:</p> |
| |
| <ul> |
| <li>For connectors using JSSE implementation provided by JVM: |
| Added in Tomcat 5.5.33.<br> |
| Requires JRE that supports RFC 5746. For Oracle JRE that is |
| <a href="http://www.oracle.com/technetwork/java/javase/documentation/tlsreadme2-176330.html" rel="nofollow">known</a> |
| to be 6u22 or later. |
| </li> |
| <li>For connectors using APR and OpenSSL:<br> |
| TBD. See |
| <a href="security-native.html">APR/native connector security page</a>. |
| </li> |
| </ul> |
| |
| <p><strong>Important: Directory traversal</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2938" rel="nofollow">CVE-2008-2938</a></p> |
| |
| <p>Originally reported as a Tomcat vulnerability the root cause of this |
| issue is that the JVM does not correctly decode UTF-8 encoded URLs to |
| UTF-8. This exposes a directory traversal vulnerability when the |
| connector uses <code>URIEncoding="UTF-8"</code>. This directory traversal |
| is limited to the docBase of the web application.</p> |
| |
| <p>If a context is configured with <code>allowLinking="true"</code> then the |
| directory traversal vulnerability is extended to the entire file system |
| of the host server.</p> |
| |
| <p>It should also be noted that setting |
| <code>useBodyEncodingForURI="true"</code> has the same effect as setting |
| <code>URIEncoding="UTF-8"</code> when processing requests with bodies |
| encoded with UTF-8.</p> |
| |
| <p>Although the root cause was quickly identified as a JVM issue and that it |
| affected multiple JVMs from multiple vendors, it was decided to report |
| this as a Tomcat vulnerability until such time as the JVM vendors |
| provided updates to resolve this issue. For further information on the |
| status of this issue for your JVM, contact your JVM vendor.</p> |
| |
| <p>A workaround was implemented in |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=681029">revision 681029</a> |
| that protects against this and any similar character |
| encoding issues that may still exist in the JVM. This work around is |
| included in Tomcat 5.5.27 onwards.</p> |
| |
| <p><strong>JavaMail information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1754" rel="nofollow">CVE-2005-1754</a></p> |
| <p>The vulnerability described is in the web application deployed on Tomcat |
| rather than in Tomcat.</p> |
| |
| <p><strong>JavaMail information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1753" rel="nofollow">CVE-2005-1753</a></p> |
| <p>The vulnerability described is in the web application deployed on Tomcat |
| rather than in Tomcat.</p> |
| |
| </div></div></div></div></main><footer id="footer"> |
| Copyright © 1999-2026, The Apache Software Foundation |
| <br> |
| Apache Tomcat, Tomcat, Apache, the Apache Tomcat logo and the Apache logo |
| are either registered trademarks or trademarks of the Apache Software |
| Foundation. |
| </footer></div><script src="res/js/tomcat.js"></script></body></html> |