logo

Database

Business information leak In org.apache.tomcat:tomcat

Description

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions

References

1. https://github.com/apache/tomcat/commit/05c84ff8304a69a30b251f207a7b93c2c882564d2. https://github.com/apache/tomcat/commit/78dd7e6f3d8481bc3bcd71ca5b20296de12838883. https://github.com/apache/tomcat/commit/b9e06ead01984483af73f48e7861bc7897f5e84f4. https://bugzilla.redhat.com/show_bug.cgi?id=10699115. https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c048510136. https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113@%3Cdev.tomcat.apache.org%3E7. https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b@%3Cdev.tomcat.apache.org%3E8. https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95@%3Cdev.tomcat.apache.org%3E9. https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb@%3Cdev.tomcat.apache.org%3E10. https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c@%3Cdev.tomcat.apache.org%3E11. https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b@%3Cdev.tomcat.apache.org%3E12. http://advisories.mageia.org/MGASA-2014-0148.html13. http://marc.info/?l=bugtraq&m=144498216801440&w=214. http://svn.apache.org/viewvc?view=revision&revision=154952815. http://svn.apache.org/viewvc?view=revision&revision=154952916. http://svn.apache.org/viewvc?view=revision&revision=155882817. http://tomcat.apache.org/security-6.html18. http://tomcat.apache.org/security-7.html19. http://tomcat.apache.org/security-8.html20. http://www-01.ibm.com/support/docview.wss?uid=swg2166788321. http://www-01.ibm.com/support/docview.wss?uid=swg2167588622. http://www-01.ibm.com/support/docview.wss?uid=swg2167714723. http://www-01.ibm.com/support/docview.wss?uid=swg2167823124. http://www.debian.org/security/2016/dsa-353025. http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html26. http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html27. http://www.vmware.com/security/advisories/VMSA-2014-0008.html