Oval Definition:oval:org.mitre.oval:def:6564
Revision Date:2015-04-20Version:26
Title:HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthorized Access
Description:Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."
Family:unixClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2009-0781
Platform(s):HP-UX 11
Product(s):
Definition Synopsis
  • Criteria meets HP Security Bulletin HPSBUX02466
  • HP-UX B.11.23
  • AND hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03
  • OR Criteria meets HP Security Bulletin HPSBUX02466
  • HP-UX B.11.11
  • AND hpuxwsTOMCAT.TOMCAT version is less than B.5.5.27.03
  • OR Criteria meets HP Security Bulletin HPSBUX02466
  • HP-UX B.11.31
  • AND hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03
  • BACK