Apache Tomcat 5.x < 5.5.21 Multiple Vulnerabilities

This script is Copyright (C) 2010-2016 Tenable Network Security, Inc.


Synopsis :

The remote web server is affected by multiple vulnerabilities.

Description :

According to its self-reported version number, the instance of Apache
Tomcat 5.x listening on the remote host is prior to 5.5.21. It is,
therefore, affected by the following vulnerabilities :

- The remote Apache Tomcat install is vulnerable to a
cross-site scripting attack. The client supplied
Accept-Language headers are not validated which allows
an attacker to use a specially crafted URL to inject
arbitrary HTML and script code into the user's browser.
(CVE-2007-1358)

- If the remote Apache Tomcat install is configured to use
the SingleSignOn Valve, the JSESSIONIDSSO cookie does
not have the 'secure' attribute set if authentication
takes place over HTTPS. This allows the JSESSIONIDSSO
cookie to be sent to the same server when HTTP content
is requested. (CVE-2008-0128)

- The remote Apache Tomcat install is affected by an
information disclosure vulnerability. The doRead method
fails to return the proper error code for certain error
conditions, which can cause POST content to be sent to
different, and improper, requests. (CVE-2008-4308)

Note that Nessus has not tested for these issues but has instead
relied only on the application's self-reported version number.

See also :

http://issues.apache.org/bugzilla/show_bug.cgi?id=41217
http://tomcat.apache.org/security-5.html#Fixed_in_Apache_Tomcat_5.5.21

Solution :

Upgrade to Apache Tomcat version 5.5.21 or later.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS Temporal Score : 4.1
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Web Servers

Nessus Plugin ID: 46868 ()

Bugtraq ID: 24524
27365
33913

CVE ID: CVE-2007-1358
CVE-2008-0128
CVE-2008-4308

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial