The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 6.0.16Upgrade Apache Tomcat to 5.5.26 | May 17, 2012 | Dec 27, 2007 |
| Apple Osx Tomcat | — | Apply OS X security update 2008-007 | Dec 16, 2011 | Dec 27, 2007 |
| Gentoo Linux | — | Upgrade www-servers/tomcat. | Oct 30, 2017 | Dec 27, 2007 |
| Oracle_linux | — | Upgrade tomcat5-servlet-2.4-api-javadocUpgrade tomcat5-servlet-2.4-apiUpgrade tomcat5-jsp-2.0-apiUpgrade tomcat5-jsp-2.0-api-javadocUpgrade tomcat5-webappsUpgrade tomcat5-admin-webappsUpgrade tomcat5-server-libUpgrade tomcat5-jasper-javadocUpgrade tomcat5Upgrade tomcat5-common-libUpgrade tomcat5-jasper | Oct 16, 2024 | Dec 27, 2007 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Dec 23, 2007 |
| Suse | — | Upgrade tomcat55-jsp-2_0-api-javadocUpgrade tomcat55-jasperUpgrade tomcat55-admin-webappsUpgrade tomcat55-webappsUpgrade tomcat55-common-libUpgrade tomcat55-servlet-2_4-api-javadocUpgrade tomcat55-servlet-2_4-apiUpgrade apache2-mod_jkUpgrade tomcat55-server-libUpgrade tomcat55Upgrade tomcat55-jasper-javadocUpgrade tomcat55-jsp-2_0-api | Feb 17, 2015 | Dec 27, 2007 |
| Vmsa 2008 0010 | — | Apply ESX350-200806404-SG. | Nov 19, 2010 | Dec 27, 2007 |
| Vmsa 2009 0016 5 Update Apache Tomcat Version | — | Upgrade VMware ESX 3.5 to build number 226117Upgrade VMware ESX 4.0 to build number 208167 | Sep 2, 2010 | Dec 27, 2007 |
| Vmsa 2010 0005 | — | Apply ESX350-201003403-SG. | Feb 16, 2011 | Dec 27, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub