Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2007-5342

Опубликовано: 27 дек. 2007
Источник: ubuntu
Приоритет: low
EPSS Средний
CVSS2: 6.4

Описание

The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.

РелизСтатусПримечание
dapper

not-affected

devel

DNE

edgy

not-affected

feisty

not-affected

gutsy

DNE

hardy

DNE

intrepid

DNE

upstream

not-affected

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

released

5.5.25-4
edgy

ignored

end of life, was needed
feisty

ignored

end of life, was needed
gutsy

ignored

end of life, was needed
hardy

released

5.5.25-4
intrepid

released

5.5.25-4
upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 94%
0.12423
Средний

6.4 Medium

CVSS2

Связанные уязвимости

redhat
больше 17 лет назад

The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.

nvd
больше 17 лет назад

The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.

debian
больше 17 лет назад

The default catalina.policy in the JULI logging component in Apache To ...

github
около 3 лет назад

JULI logging component in Apache Tomcat does not restrict certain permissions for web applications

oracle-oval
больше 17 лет назад

ELSA-2008-0042: Moderate: tomcat security update (MODERATE)

EPSS

Процентиль: 94%
0.12423
Средний

6.4 Medium

CVSS2

Уязвимость CVE-2007-5342