CVE-2007-0450
Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a ..
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 90.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 90.77% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- apache/http server · apache/tomcat
- Source
- secalert@redhat.com
References
- http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspxBroken Link
- http://docs.info.apple.com/article.html?artnum=306172Third Party Advisory
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795Broken Link
- http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.htmlMailing List, Third Party Advisory
- http://lists.vmware.com/pipermail/security-announce/2008/000003.htmlThird Party Advisory
- http://secunia.com/advisories/24732Third Party Advisory
- http://secunia.com/advisories/25106Third Party Advisory
- http://secunia.com/advisories/25280Third Party Advisory
- http://secunia.com/advisories/26235Third Party Advisory
- http://secunia.com/advisories/26660Third Party Advisory
- http://secunia.com/advisories/27037Third Party Advisory
- http://secunia.com/advisories/28365Third Party Advisory
- http://secunia.com/advisories/30899Third Party Advisory
- http://secunia.com/advisories/30908Third Party Advisory
- http://secunia.com/advisories/33668Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200705-03.xmlThird Party Advisory
- http://securityreason.com/securityalert/2446Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1Broken Link
- http://support.avaya.com/elmodocs2/security/ASA-2007-206.htmThird Party Advisory
- http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540Broken Link, Third Party Advisory
- http://tomcat.apache.org/security-4.htmlVendor Advisory
- http://tomcat.apache.org/security-5.htmlVendor Advisory
- http://tomcat.apache.org/security-6.htmlVendor Advisory
- http://www.fujitsu.com/global/support/software/security/products-f/interstage-200702e.htmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:241Third Party Advisory
- http://www.novell.com/linux/security/advisories/2007_15_sr.htmlBroken Link
- http://www.novell.com/linux/security/advisories/2007_5_sr.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2007-0327.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0360.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0261.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.