危険度:
  CVE識別番号: CVE-2002-1148
  情報公開日: 7 21, 2015

  概要

The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.

  トレンドマイクロの対策

Apply associated Trend Micro DPI Rules.

  対応方法

  Trend Micro Deep Security DPI Rule Number: 1000637
  Trend Micro Deep Security DPI Rule Name: 1000637 - Tomcat 4.x JSP source code exposure

  影響を受けるソフトウェア

  • Apache Software Foundation Tomcat 3.0
  • Apache Software Foundation Tomcat 3.1
  • Apache Software Foundation Tomcat 3.1.1
  • Apache Software Foundation Tomcat 3.2
  • Apache Software Foundation Tomcat 3.2.1
  • Apache Software Foundation Tomcat 3.2.2 beta 2
  • Apache Software Foundation Tomcat 3.2.3
  • Apache Software Foundation Tomcat 3.2.4
  • Apache Software Foundation Tomcat 3.3
  • Apache Software Foundation Tomcat 3.3.1
  • Apache Software Foundation Tomcat 4.0
  • Apache Software Foundation Tomcat 4.0.1
  • Apache Software Foundation Tomcat 4.0.2
  • Apache Software Foundation Tomcat 4.0.3
  • Apache Software Foundation Tomcat 4.0.4
  • Apache Software Foundation Tomcat 4.1
  • Apache Software Foundation Tomcat 4.1.10
  • Apache Software Foundation Tomcat 4.1.3 beta
  • Apache Software Foundation Tomcat 4.1.9 beta