Vulnerability Name:

CVE-2002-1857 (CCN-9446)

Assigned:2002-06-28
Published:2002-06-28
Updated:2008-09-05
Summary:jo! jo Webserver 1.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2002-1855

Source: MITRE
Type: CNA
CVE-2002-1856

Source: MITRE
Type: CNA
CVE-2002-1857

Source: MITRE
Type: CNA
CVE-2002-1858

Source: MITRE
Type: CNA
CVE-2002-1859

Source: MITRE
Type: CNA
CVE-2002-1860

Source: MITRE
Type: CNA
CVE-2002-1861

Source: BUGTRAQ
Type: UNKNOWN
20020628 wp-02-0002: 'WEB-INF' Folder accessible in Multiple Web Application Servers

Source: CCN
Type: Oracle Web site
Welcome to Oracle.com online services

Source: CCN
Type: SourceForge.net
Project: jo!: Summary

Source: XF
Type: Patch
webinf-dot-file-retrieval(9446)

Source: CCN
Type: Macromedia Security Bulletin MPSB02-06
Cumulative Security Patch available for JRun 3.0, 3.1 and 4.0

Source: CCN
Type: Orion Web site
Orion Application Server

Source: CCN
Type: OSVDB ID: 44525
Oracle Application Server Crafted Request WEB-INF Directory Information Disclosure

Source: CCN
Type: OSVDB ID: 53449
Macromedia JRun Crafted Request WEB-INF Directory Information Disclosure

Source: CCN
Type: OSVDB ID: 53450
HP Application Server on Windows Crafted Request WEB-INF Directory Information Disclosure

Source: CCN
Type: OSVDB ID: 53451
jo! jo Webserver on Windows Crafted Request WEB-INF Directory Information Disclosure

Source: CCN
Type: OSVDB ID: 53452
Orion Application Server Crafted Request WEB-INF Directory Information Disclosure

Source: CCN
Type: OSVDB ID: 53453
Pramati Server on Windows Crafted Request WEB-INF Directory Information Disclosure

Source: CCN
Type: OSVDB ID: 53454
Sybase Enterprise Application Server on Windows Crafted Request WEB-INF Directory Information Disclosure

Source: CCN
Type: Pramati Technologies Web site
The J2EE Infrastructure Company

Source: BID
Type: Patch
5119

Source: CCN
Type: BID-5119
Multiple Vendor WEB-INF Directory Contents Disclosure Vulnerability

Source: CCN
Type: Sybase, Inc. Web site
Sybase, Inc. EAServer

Source: CCN
Type: Westpoint Security Advisory wp-02-0002
'WEB-INF' Folder accessible in Multiple Web Application Servers

Source: MISC
Type: UNKNOWN
http://www.westpoint.ltd.uk/advisories/wp-02-0002.txt

Source: XF
Type: UNKNOWN
webinf-dot-file-retrieval(9446)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:jo:jo_webserver:1.0_rc1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:macromedia:jrun:3.0:*:*:*:*:*:*:*
  • OR cpe:/a:macromedia:jrun:3.1:*:*:*:*:*:*:*
  • OR cpe:/a:macromedia:jrun:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:orionserver:orion_application_server:1.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:easerver:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:hp:application_server:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:pramati:pramati_server:3.0:*:*:*:*:*:*:*
  • AND
  • cpe:/a:oracle:application_server:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    jo jo webserver 1.0_rc1
    macromedia jrun 3.0
    macromedia jrun 3.1
    macromedia jrun 4.0
    orionserver orion application server 1.5.3
    sybase easerver 4.0
    hp application server 8.0
    pramati pramati server 3.0
    oracle application server *