CVE-2009-2901
The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication…
Does this matter?
Lower severity and a low EPSS score (8.15%). Track it; it rarely justifies an emergency change on its own.
Description
The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 8.15% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- apache/tomcat
- Source
- secalert@redhat.com
References
- http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html
- http://lists.opensuse.org/opensuse-updates/2012-12/msg00089.html
- http://lists.opensuse.org/opensuse-updates/2012-12/msg00090.html
- http://lists.opensuse.org/opensuse-updates/2013-01/msg00037.html
- http://marc.info/?l=bugtraq&m=127420533226623&w=2
- http://marc.info/?l=bugtraq&m=133469267822771&w=2
- http://marc.info/?l=bugtraq&m=139344343412337&w=2
- http://secunia.com/advisories/38316Vendor Advisory
- http://secunia.com/advisories/38346Vendor Advisory
- http://secunia.com/advisories/38541
- http://secunia.com/advisories/39317
- http://secunia.com/advisories/43310
- http://secunia.com/advisories/57126
- http://securitytracker.com/id?1023503
- http://support.apple.com/kb/HT4077
- http://svn.apache.org/viewvc?rev=892815&view=revPatch
- http://svn.apache.org/viewvc?rev=902650&view=revPatch
- http://tomcat.apache.org/security-5.htmlPatch, Vendor Advisory
- http://tomcat.apache.org/security-6.htmlPatch, Vendor Advisory
- http://ubuntu.com/usn/usn-899-1
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:176
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:177
- http://www.securityfocus.com/archive/1/509151/100/0/threaded
- http://www.securityfocus.com/archive/1/516397/100/0/threaded
- http://www.securityfocus.com/bid/37942
- http://www.vmware.com/security/advisories/VMSA-2011-0003.html
- http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html
- http://www.vupen.com/english/advisories/2010/0213Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55856
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.