|
CVE-2002-2272
|
High
|
2002-12-31
|
Mitigation candidate
|
Working exploit published
|
Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
|
|
CVE-2002-2072
|
Medium
|
2002-12-31
|
Mitigation candidate
|
Working exploit published
|
java.security.AccessController in Sun Java Virtual Machine (JVM) in JRE 1.2.2 and 1.3.1 allows remote attackers to cause a denial of service (JVM crash) via a Java program that calls the doPrivileged method with a null argument.
|
|
CVE-2002-2009
|
Medium
|
2002-12-31
|
No exploit published
|
No public exploit
|
Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %20/, which leaks the pathname in an error message.
|
|
CVE-2002-2008
|
Medium
|
2002-12-31
|
No exploit published
|
No public exploit
|
Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the information in an error message.
|
|
CVE-2002-2007
|
Medium
|
2002-12-31
|
Mitigation candidate
|
Working exploit published
|
The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.
|
|
CVE-2002-2006
|
Medium
|
2002-12-31
|
Mitigation candidate
|
Working exploit published
|
The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.
|
|
CVE-2002-1987
|
Medium
|
2002-12-31
|
Protected by RASP
|
No public exploit
|
Directory traversal vulnerability in view_source.jsp in Resin 2.1.2 allows remote attackers to read arbitrary files via a "\.." (backslash dot dot).
|
|
CVE-2002-1895
|
Medium
|
2002-12-31
|
No fix identified
|
No public exploit
|
The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.
|
|
CVE-2002-1882
|
High
|
2002-12-31
|
No fix identified
|
No public exploit
|
Unknown vulnerability in AolSecurityPrivate.class in Oracle E-Business Suite 11i 11.1 through 11.6 allows remote attackers to bypass user authentication checks via unknown attack vectors.
|
|
CVE-2002-1666
|
Medium
|
2002-12-31
|
No fix identified
|
No public exploit
|
Unknown vulnerability in Oracle E-Business Suite 11i.1 through 11i.6 allows remote attackers to execute unauthorized PL/SQL procedures by modifying the Oracle Applications URL.
|
|
CVE-2002-1153
|
Medium
|
2002-10-11
|
No fix identified
|
No public exploit
|
IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host".
|
|
CVE-2002-1148
|
Medium
|
2002-10-11
|
Mitigation candidate
|
Working exploit published
|
The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.
|
|
CVE-2002-1042
|
Medium
|
2002-10-04
|
Protected by RASP
|
Working exploit published
|
Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter.
|
|
CVE-2002-0936
|
Medium
|
2002-10-04
|
Mitigation candidate
|
Working exploit published
|
The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).
|
|
CVE-2002-0935
|
Medium
|
2002-10-04
|
No exploit published
|
No public exploit
|
Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang.
|
|
CVE-2002-0493
|
High
|
2002-08-12
|
No exploit published
|
No public exploit
|
Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.
|
|
CVE-2002-0682
|
High
|
2002-07-23
|
Mitigation candidate
|
Working exploit published
|
Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.
|
|
CVE-2002-1640
|
Medium
|
2002-04-01
|
No fix identified
|
No public exploit
|
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to inject arbitrary web script or HTML via (1) Text Features in the DHTML UI or (2) the test parameter to the oracle.apps.cz.servlet.UiServlet servlet.
|
|
CVE-2002-1639
|
High
|
2002-04-01
|
No fix identified
|
No public exploit
|
Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to obtain sensitive information via a request to the oracle.apps.cz.servlet.UiServlet servlet with the test parameter set to "version" or "host".
|
|
CVE-2000-1210
|
Medium
|
2002-03-22
|
Protected by RASP
|
No public exploit
|
Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.
|