Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2007-5342

Опубликовано: 23 дек. 2007
Источник: redhat
EPSS Средний

Описание

The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=427216Apache Tomcat's default security policy is too open

EPSS

Процентиль: 94%
0.12423
Средний

Связанные уязвимости

ubuntu
больше 17 лет назад

The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.

nvd
больше 17 лет назад

The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.

debian
больше 17 лет назад

The default catalina.policy in the JULI logging component in Apache To ...

github
около 3 лет назад

JULI logging component in Apache Tomcat does not restrict certain permissions for web applications

oracle-oval
больше 17 лет назад

ELSA-2008-0042: Moderate: tomcat security update (MODERATE)

EPSS

Процентиль: 94%
0.12423
Средний