FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2015-5345

This CVE name corresponds to:

Entered Topic
2016-02-28 tomcat -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2015-5345
Phase Assigned(20150701)

Description

The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a directory via a URL that lacks a trailing / (slash) character.

References

Source Reference
BUGTRAQ 20160222 [SECURITY] CVE-2015-5345 Apache Tomcat Directory disclosure
MISC http://www.qcsec.com/blog/CVE-2015-5345-apache-tomcat-vulnerability.html
CONFIRM http://svn.apache.org/viewvc?view=revision&revision=1715206
CONFIRM http://svn.apache.org/viewvc?view=revision&revision=1715207
CONFIRM http://svn.apache.org/viewvc?view=revision&revision=1715213
CONFIRM http://svn.apache.org/viewvc?view=revision&revision=1715216
CONFIRM http://svn.apache.org/viewvc?view=revision&revision=1716882
CONFIRM http://svn.apache.org/viewvc?view=revision&revision=1716894
CONFIRM http://svn.apache.org/viewvc?view=revision&revision=1717209
CONFIRM http://svn.apache.org/viewvc?view=revision&revision=1717212
CONFIRM http://svn.apache.org/viewvc?view=revision&revision=1717216
CONFIRM http://tomcat.apache.org/security-6.html
CONFIRM http://tomcat.apache.org/security-7.html
CONFIRM http://tomcat.apache.org/security-8.html
CONFIRM http://tomcat.apache.org/security-9.html
CONFIRM https://bz.apache.org/bugzilla/show_bug.cgi?id=58765
CONFIRM https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150442
CONFIRM https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158626
CONFIRM https://h20565.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150442
CONFIRM https://h20565.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158626
CONFIRM https://kc.mcafee.com/corporate/index?page=content&id=SB10156
DEBIAN DSA-3530
DEBIAN DSA-3609
DEBIAN DSA-3552
UBUNTU USN-3024-1