CVE-2015-5345
The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a directory via a URL that lacks a trailing / (slash) character.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 18.38% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- debian/debian linux · apache/tomcat · canonical/ubuntu linux
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00047.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00069.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00082.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00085.html
- http://marc.info/?l=bugtraq&m=145974991225029&w=2
- http://packetstormsecurity.com/files/135892/Apache-Tomcat-Directory-Disclosure.html
- http://rhn.redhat.com/errata/RHSA-2016-1089.html
- http://rhn.redhat.com/errata/RHSA-2016-2045.html
- http://rhn.redhat.com/errata/RHSA-2016-2599.html
- http://seclists.org/bugtraq/2016/Feb/146
- http://seclists.org/fulldisclosure/2016/Feb/122
- http://svn.apache.org/viewvc?view=revision&revision=1715206
- http://svn.apache.org/viewvc?view=revision&revision=1715207
- http://svn.apache.org/viewvc?view=revision&revision=1715213
- http://svn.apache.org/viewvc?view=revision&revision=1715216
- http://svn.apache.org/viewvc?view=revision&revision=1716882
- http://svn.apache.org/viewvc?view=revision&revision=1716894
- http://svn.apache.org/viewvc?view=revision&revision=1717209
- http://svn.apache.org/viewvc?view=revision&revision=1717212
- http://svn.apache.org/viewvc?view=revision&revision=1717216
- http://tomcat.apache.org/security-6.htmlVendor Advisory
- http://tomcat.apache.org/security-7.htmlVendor Advisory
- http://tomcat.apache.org/security-8.htmlVendor Advisory
- http://tomcat.apache.org/security-9.htmlVendor Advisory
- http://www.debian.org/security/2016/dsa-3530
- http://www.debian.org/security/2016/dsa-3552
- http://www.debian.org/security/2016/dsa-3609
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.