Vulnerability Name: | CCN-13086 | ||||||
Published: | 2003-03-16 | ||||||
Updated: | 2003-03-16 | ||||||
Summary: | The mod_jk module for Apache is vulnerable to a format string attack. A format string vulnerability in the Apache mod_jk modules may allow a remote attacker remote access with the privileges of the running Web server. Mod_jk must be specifically configured to be logging request data that is under the user's control for this bug to be exploitable. | ||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||
CVSS v2 Severity: | 7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||
Vulnerability Consequences: | Gain Access | ||||||
References: | Source: CCN Type: Tomcat Developers List, 16 Mar 2003 02:59:44 -0000 cvs commit: jakarta-tomcat-connectors/jk/native/apache-2.0 mod_jk.c Source: XF Type: UNKNOWN jakarta-tomcat-modjk-format-string(13086) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |