PT-2017-14152 · Apache+3 · Apache Tomcat+3

CVE-2017-15706

·

Publicado

2017-11-30

·

Atualizado

2023-12-08

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 9.0.0.M22 through 9.0.1 Apache Tomcat versions 8.5.16 through 8.5.23 Apache Tomcat versions 8.0.45 through 8.0.47 Apache Tomcat versions 7.0.79 through 7.0.82
Description The issue concerns the documentation of the search algorithm used by the CGI Servlet in Apache Tomcat. An update to this documentation was incorrect, which may have caused some scripts to fail execution as expected, while others may have been executed unexpectedly. However, the actual behavior of the CGI servlet has not changed, only its documentation was incorrect and has been corrected.
Recommendations For Apache Tomcat versions 9.0.0.M22 through 9.0.1, update the documentation to reflect the correct search algorithm used by the CGI Servlet. For Apache Tomcat versions 8.5.16 through 8.5.23, update the documentation to reflect the correct search algorithm used by the CGI Servlet. For Apache Tomcat versions 8.0.45 through 8.0.47, update the documentation to reflect the correct search algorithm used by the CGI Servlet. For Apache Tomcat versions 7.0.79 through 7.0.82, update the documentation to reflect the correct search algorithm used by the CGI Servlet.

Exploit

Correção

Improperly Implemented Security Check for Standard

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1731
CVE-2017-15706
GHSA-372Q-33VH-8MPC
MGASA-2018-0149
SUSE-SU-2018:0817-1
SUSE-SU-2018:3261-1
SUSE-SU-2018:3388-1
USN-3665-1

Produtos afetados

Alt Linux
Apache Tomcat
Suse
Ubuntu