Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-2071

Опубликовано: 10 мая 2013
Источник: redhat
CVSS2: 2.6

Описание

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.

Отчет

This flaw only affects tomcat 7. Tomcat 5 and 6 are not affected. The jbossweb servlet container is also not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5tomcat5Not affected
Red Hat Enterprise Linux 6tomcat6Not affected
Red Hat JBoss Enterprise Web Server 1eap5Not affected
Red Hat JBoss Enterprise Web Server 1eap6Not affected
Red Hat JBoss Enterprise Web Server 1tomcat5Not affected
Red Hat JBoss Enterprise Web Server 1tomcat6Not affected
Red Hat JBoss Enterprise Web Server 2 for RHEL 5apache-commons-daemon-eap6FixedRHSA-2013:101103.07.2013
Red Hat JBoss Enterprise Web Server 2 for RHEL 5apache-commons-daemon-jsvc-eap6FixedRHSA-2013:101103.07.2013
Red Hat JBoss Enterprise Web Server 2 for RHEL 5apache-commons-pool-eap6FixedRHSA-2013:101103.07.2013
Red Hat JBoss Enterprise Web Server 2 for RHEL 5dom4jFixedRHSA-2013:101103.07.2013

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=961803tomcat: Information disclosure in asynchronous context when using AsyncListeners that threw RuntimeExceptions

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
около 12 лет назад

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.

nvd
около 12 лет назад

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.

debian
около 12 лет назад

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7 ...

github
около 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

2.6 Low

CVSS2