ISOMAN

CVE

CVE-2015-5345

The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a directory via a URL that lacks a trailing / (slash) character.

Severity
MEDIUM
CVSS
5.3
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00047.html
  2. http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00069.html
  3. http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00082.html
  4. http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00085.html
  5. http://marc.info/?l=bugtraq&m=145974991225029&w=2
  6. http://packetstormsecurity.com/files/135892/Apache-Tomcat-Directory-Disclosure.html
  7. http://rhn.redhat.com/errata/RHSA-2016-1089.html
  8. http://rhn.redhat.com/errata/RHSA-2016-2045.html
  9. http://rhn.redhat.com/errata/RHSA-2016-2599.html
  10. http://seclists.org/bugtraq/2016/Feb/146
  11. http://seclists.org/fulldisclosure/2016/Feb/122
  12. http://svn.apache.org/viewvc?view=revision&revision=1715206
  13. http://svn.apache.org/viewvc?view=revision&revision=1715207
  14. http://svn.apache.org/viewvc?view=revision&revision=1715213
  15. http://svn.apache.org/viewvc?view=revision&revision=1715216
  16. http://svn.apache.org/viewvc?view=revision&revision=1716882
  17. http://svn.apache.org/viewvc?view=revision&revision=1716894
  18. http://svn.apache.org/viewvc?view=revision&revision=1717209
  19. http://svn.apache.org/viewvc?view=revision&revision=1717212
  20. http://svn.apache.org/viewvc?view=revision&revision=1717216