Lucene search

K
kasperskyKaspersky LabKLA10070
HistoryMay 31, 2014 - 12:00 a.m.

KLA10070 RLF vulnerability in Apache Tomcat

2014-05-3100:00:00
Kaspersky Lab
threats.kaspersky.com
31

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

8.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

53.6%

An improper class constriction vulnerability was found in Apache Tomcat. By exploiting this vulnerability malicious users can read arbitrary files. This vulnerability can be exploited from the network at a point related to the XML parser via a specially designed web application.

Original advisories

Apache changelog

Related products

Apache-Tomcat

CVE list

CVE-2014-0119 warning

Solution

Update to latest version

Impacts

  • RLF

Read Local Files. Exploitation of vulnerabilities with this impact can lead to reading some inaccessible files. Files that can be read depends on conсrete program errors.

Affected Products

  • Apache Tomcat versions 6.0.40 and earlierApache Tomcat 7 versions 7.0.53 and earlierApache Tomcat 8 versions 8.0.5 and earlier

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

8.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

53.6%