Apache Tomcat 4.x < 4.1.39 Multiple Vulnerabilities

This script is Copyright (C) 2010-2014 Tenable Network Security, Inc.


Synopsis :

The remote web server may be affected by multiple vulnerabilities.

Description :

According to its self-reported version number, the instance of Apache
Tomcat 4.x listening on the remote host is earlier than 4.1.39 and,
therefore, may be affected by one or more of the following
vulnerabilities :

- If the remote Apache Tomcat install is configured to use
the SingleSignOn Valve, the JSESSIONIDSSO cookie does
not have the 'secure' attribute set if authentication
takes place over HTTPS. This allows the JSESSIONIDSSO
cookie to be sent to the same server when HTTP content
is requested. (CVE-2008-0128)

- The remote Apache Tomcat install is vulnerable to a
cross-site scripting attack. Improper input validation
allows a remote attacker to inject arbitrary script
code or HTML into the message argument used by the
HttpServletResponse.sendError method. (CVE-2008-1232)

- If the remote Apache Tomcat install contains pages
using the RequestDispatcher object, a directory
traversal attack may be possible. This allows an
attacker to select one or more of the input parameters
and provide specific values leading to access of
potentially sensitive files. (CVE-2008-2370)

Note that Nessus did not actually test for the flaws but instead has
relied on the version in Tomcat's banner or error page so this may be
a false positive.

See also :

http://tomcat.apache.org/security-4.html#Fixed_in_Apache_Tomcat_4.1.39

Solution :

Update Apache Tomcat to version 4.1.39 or later.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS Temporal Score : 4.3
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : true

Family: Web Servers

Nessus Plugin ID: 46867 ()

Bugtraq ID: 27365
30496
30494

CVE ID: CVE-2008-0128
CVE-2008-1232
CVE-2008-2370