Apache Tomcat < 3.3.1a Directory Listing and File Disclosure

medium Nessus Network Monitor Plugin ID 1466

Synopsis

The remote web server is affected by an information disclosure vulnerability.

Description

Apache Tomcat (prior to 3.3.1a) is affected by a directory listing and file disclosure vulnerability.

By requesting URLs containing a null character, remote attackers can list directories even when an index.html or other file is present or obtain unprocessed source code for a JSP file.

Also note that, when deployed with JDK 1.3.1 or earlier, Tomcat allows files outside of the application directory to be accessed because 'web.xml' files are read with trusted privileges.

Solution

Upgrade to Tomcat 3.3.1a or higher.

Plugin Details

Severity: Medium

ID: 1466

Family: Web Servers

Published: 8/20/2004

Updated: 3/6/2019

Nessus ID: 11438

Risk Information

VPR

Risk Factor: Medium

Score: 4.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: cpe:/a:apache:tomcat

Patch Publication Date: 3/18/2003

Vulnerability Publication Date: 1/25/2003

Reference Information

CVE: CVE-2003-0042

BID: 6721