Apache Tomcat which is shipped with WebSphere Application Server Community Edition (WASCE) 3.0.0.4 is vulnerable to a remote attacker to traverse directories on the system.
CVEID: CVE-2015-5174**
DESCRIPTION:** Apache Tomcat could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing “dot dot” sequences (/…/) in the getResource(), getResourceAsStream() and getResourcePaths() ServletContext methods to obtain a directory listing for the directory.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/110860 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
WebSphere Application Server Community Edition 3.0.0.4
Please follow the instruction below.
1.Please download the patch file.CVE-2015-5174_patch.zip
2.Unzip the attached file into the WebSphere Application Server Community Edition installation directory, and ensure the files listed in the zip file mergedinto the ones in the server installation directory.
3.Start WASCE 3.0.0.4 server with the cache cleaned, for example,
Window
<WAS_CE_HOME>\bin\startup -c
Unix/Linux
<WAS_CE_HOME>/bin/startup.sh -c
CPE | Name | Operator | Version |
---|---|---|---|
websphere application server community edition | eq | 3.0.0.4 |