Lucene search

K
githubGitHub Advisory DatabaseGHSA-W65J-CMQC-37P2
HistoryMay 01, 2022 - 6:32 p.m.

JULI logging component in Apache Tomcat does not restrict certain permissions for web applications

2022-05-0118:32:22
CWE-284
GitHub Advisory Database
github.com
13

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

0.004 Low

EPSS

Percentile

75.2%

The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.

Affected configurations

Vulners
Node
org.apache.tomcat\tomcatMatchjuli
OR
org.apache.tomcat\tomcatMatchjuli

References

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

0.004 Low

EPSS

Percentile

75.2%