Oval Definition:oval:org.mitre.oval:def:6445
Revision Date:2015-04-20Version:26
Title:HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthorized Access
Description:Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.
Family:unixClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2008-5515
Platform(s):HP-UX 11
Product(s):
Definition Synopsis
  • Criteria meets HP Security Bulletin HPSBUX02466
  • HP-UX B.11.23
  • AND hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03
  • OR Criteria meets HP Security Bulletin HPSBUX02466
  • HP-UX B.11.11
  • AND hpuxwsTOMCAT.TOMCAT version is less than B.5.5.27.03
  • OR Criteria meets HP Security Bulletin HPSBUX02466
  • HP-UX B.11.31
  • AND hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03
  • BACK