Lucene search

K
ubuntuUbuntuUSN-899-1
HistoryFeb 11, 2010 - 12:00 a.m.

Tomcat vulnerabilities

2010-02-1100:00:00
ubuntu.com
40

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

AI Score

4.5

Confidence

High

EPSS

0.005

Percentile

76.4%

Releases

  • Ubuntu 9.10
  • Ubuntu 9.04
  • Ubuntu 8.10

Packages

  • tomcat6 -

Details

It was discovered that Tomcat did not correctly validate WAR filenames or
paths when deploying. A remote attacker could send a specially crafted WAR
file to be deployed and cause arbitrary files and directories to be
created, overwritten, or deleted.

Rows per page:
1-10 of 261

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

AI Score

4.5

Confidence

High

EPSS

0.005

Percentile

76.4%