Tomcat 4.x JSP source code exposure

  Severity: MEDIUM
  CVE Identifier: CVE-2002-1148
  Advisory Date: JUL 21, 2015

  DESCRIPTION

The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.

  TREND MICRO PROTECTION INFORMATION

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1000637
  Trend Micro Deep Security DPI Rule Name: 1000637 - Tomcat 4.x JSP source code exposure

  AFFECTED SOFTWARE AND VERSION

  • Apache Software Foundation Tomcat 3.0
  • Apache Software Foundation Tomcat 3.1
  • Apache Software Foundation Tomcat 3.1.1
  • Apache Software Foundation Tomcat 3.2
  • Apache Software Foundation Tomcat 3.2.1
  • Apache Software Foundation Tomcat 3.2.2 beta 2
  • Apache Software Foundation Tomcat 3.2.3
  • Apache Software Foundation Tomcat 3.2.4
  • Apache Software Foundation Tomcat 3.3
  • Apache Software Foundation Tomcat 3.3.1
  • Apache Software Foundation Tomcat 4.0
  • Apache Software Foundation Tomcat 4.0.1
  • Apache Software Foundation Tomcat 4.0.2
  • Apache Software Foundation Tomcat 4.0.3
  • Apache Software Foundation Tomcat 4.0.4
  • Apache Software Foundation Tomcat 4.1
  • Apache Software Foundation Tomcat 4.1.10
  • Apache Software Foundation Tomcat 4.1.3 beta
  • Apache Software Foundation Tomcat 4.1.9 beta

Featured Stories