PT-2007-6410 · Apache+1 · Apache Tomcat+1

CVE-2007-5342

·

Publicado

2007-12-27

·

Atualizado

2023-02-13

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Apache Tomcat versions 5.5.9 through 5.5.25 Apache Tomcat versions 6.0.0 through 6.0.15
Description: The default catalina.policy in the JULI logging component does not restrict certain permissions for web applications, allowing attackers to modify logging configuration options and overwrite arbitrary files. This can be achieved by changing attributes in the org.apache.juli.FileHandler handler, such as the level, directory, and prefix. The JULI logging component allows web applications to provide their own logging configurations, and the default security policy does not restrict this configuration, enabling an untrusted web application to add files or overwrite existing files where the Tomcat process has the necessary file permissions.
Recommendations: For Apache Tomcat versions 5.5.9 through 5.5.25, restrict the permissions for web applications in the catalina.policy file to prevent modification of logging configuration options. For Apache Tomcat versions 6.0.0 through 6.0.15, restrict the permissions for web applications in the catalina.policy file to prevent modification of logging configuration options. As a temporary workaround, consider disabling the org.apache.juli.FileHandler handler until a patch is available.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5342
DSA-1447-1
GHSA-W65J-CMQC-37P2
RHSA-2008:0042
RHSA-2008:0195
RHSA-2008:0831
RHSA-2008:0832
RHSA-2008:0833
RHSA-2008:0834
RHSA-2008:0862
RHSA-2008_0042

Produtos afetados

Apache Tomcat
Red Hat