[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1468 tomcat5.5 -- several vulnerabilities

ID: oval:org.mitre.oval:def:7601Date: (C)2009-12-15   (M)2023-11-13
Class: PATCHFamily: unix




Several remote vulnerabilities have been discovered in the Tomcat servlet and JSP engine. The Common Vulnerabilities and Exposures project identifies the following problems: Olaf Kock discovered that HTTPS encryption was insufficiently enforced for single-sign-on cookies, which could result in information disclosure. It was discovered that the Manager and Host Manager web applications performed insufficient input sanitising, which could lead to cross site scripting. This update also adapts the tomcat5.5-webapps package to the tightened JULI permissions introduced in the previous tomcat5.5 DSA. However, it should be noted, that the tomcat5.5-webapps is for demonstration and documentation purposes only and should not be used for production systems. The old stable distribution (sarge) doesn't contain tomcat5.5.

Platform:
Debian 4.0
Product:
tomcat5.5
Reference:
DSA-1468
CVE-2008-0128
CVE-2007-2450
CVE    2
CVE-2007-2450
CVE-2008-0128
CPE    1
cpe:/o:debian:debian_linux:4.0

© SecPod Technologies