Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.804519
Kategorie:Web Servers
Titel:Apache Tomcat Multiple Vulnerabilities - 01 (Mar 2014)
Zusammenfassung:Apache Tomcat is prone to multiple vulnerabilities.
Beschreibung:Summary:
Apache Tomcat is prone to multiple vulnerabilities.

Vulnerability Insight:
Flaws are due to the HTTP connector or AJP connector which do not properly
handle certain inconsistent HTTP request headers.

Vulnerability Impact:
Successful exploitation will allow remote attackers to conduct session
fixation attacks and manipulate certain data.

Affected Software/OS:
Apache Tomcat version before 6.0.39, 7.x before 7.0.47, and 8.x before
8.0.0-RC3

Solution:
Upgrade to version 6.0.39 or 7.0.47 or 8.0.0-RC3 or later.

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2013-4286
BugTraq ID: 65773
http://www.securityfocus.com/bid/65773
Bugtraq: 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/534161/100/0/threaded
Debian Security Information: DSA-3530 (Google Search)
http://www.debian.org/security/2016/dsa-3530
http://seclists.org/fulldisclosure/2014/Dec/23
HPdes Security Advisory: HPSBOV03503
http://marc.info/?l=bugtraq&m=144498216801440&w=2
HPdes Security Advisory: HPSBUX03150
http://marc.info/?l=bugtraq&m=141390017113542&w=2
http://www.mandriva.com/security/advisories?name=MDVSA-2015:052
https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b@%3Cdev.tomcat.apache.org%3E
RedHat Security Advisories: RHSA-2014:0343
http://rhn.redhat.com/errata/RHSA-2014-0343.html
RedHat Security Advisories: RHSA-2014:0344
http://rhn.redhat.com/errata/RHSA-2014-0344.html
RedHat Security Advisories: RHSA-2014:0345
http://rhn.redhat.com/errata/RHSA-2014-0345.html
RedHat Security Advisories: RHSA-2014:0686
https://rhn.redhat.com/errata/RHSA-2014-0686.html
http://secunia.com/advisories/57675
http://secunia.com/advisories/59036
http://secunia.com/advisories/59675
http://secunia.com/advisories/59722
http://secunia.com/advisories/59724
http://secunia.com/advisories/59733
http://secunia.com/advisories/59873
http://www.ubuntu.com/usn/USN-2130-1
CopyrightCopyright (C) 2014 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.