Apache Tomcat Directory Listing and File Disclosure

medium Nessus Plugin ID 11438

Language:

Synopsis

The remote web server is affected by an information disclosure vulnerability.

Description

Apache Tomcat (prior to 3.3.1a) is affected by a directory listing and file disclosure vulnerability.

By requesting URLs containing a null character, remote attackers can list directories even when an index.html or other file is present or obtain unprocessed source code for a JSP file.

Also note that, when deployed with JDK 1.3.1 or earlier, Tomcat allows files outside of the application directory to be accessed because 'web.xml' files are read with trusted privileges.

Solution

Upgrade to Apache Tomcat version 4.1.18 or later.

Plugin Details

Severity: Medium

ID: 11438

File Name: tomcat_directory_listing_and_file_disclosure.nasl

Version: 1.32

Type: remote

Family: CGI abuses

Published: 3/22/2003

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:apache:tomcat

Required KB Items: installed_sw/Apache Tomcat

Exploit Ease: No exploit is required

Patch Publication Date: 3/18/2003

Vulnerability Publication Date: 1/25/2003

Reference Information

CVE: CVE-2003-0042, CVE-2003-0043

BID: 6721, 6722