CVE-2009-0783
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld…
Does this matter?
Lower severity and a low EPSS score (0.81%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.
- CVSS 3.0
- 4.2 MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 0.81% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apache/tomcat
- Source
- secalert@redhat.com
References
- http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=127420533226623&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=129070310906557&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=136485229118404&w=2Third Party Advisory
- http://secunia.com/advisories/35685Vendor Advisory
- http://secunia.com/advisories/35788Vendor Advisory
- http://secunia.com/advisories/37460Vendor Advisory
- http://secunia.com/advisories/42368Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-263529-1Third Party Advisory
- http://support.apple.com/kb/HT4077Third Party Advisory
- http://svn.apache.org/viewvc?rev=652592&view=revPatch
- http://svn.apache.org/viewvc?rev=681156&view=revPatch
- http://svn.apache.org/viewvc?rev=739522&view=revPatch
- http://svn.apache.org/viewvc?rev=781542&view=revPatch
- http://svn.apache.org/viewvc?rev=781708&view=revPatch
- http://tomcat.apache.org/security-4.htmlPatch, Vendor Advisory
- http://tomcat.apache.org/security-5.htmlPatch, Vendor Advisory
- http://tomcat.apache.org/security-6.htmlPatch, Vendor Advisory
- http://www.debian.org/security/2011/dsa-2207Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:136Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:138Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:176Third Party Advisory
- http://www.securityfocus.com/archive/1/504090/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/507985/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35416Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1022336Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlThird Party Advisory
- http://www.vupen.com/english/advisories/2009/1856Vendor Advisory
- http://www.vupen.com/english/advisories/2009/3316Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.