Limited directory traversal in Oracle Linux and Apache Tomcat - CVE-2015-5174

 

Limited directory traversal in Oracle Linux and Apache Tomcat - CVE-2015-5174

Published: August 5, 2016 / Updated: January 11, 2017


Vulnerability identifier: #VU261
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-5174
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to obtain potentially sensitive information.

The vulnerability exists due to incorrect validation of paths in getResource(), getResourceAsStream() and getResourcePaths() methods within ServletContext. A local attacker can bypass security manager restrictions using directory traversal sequences and view directory listing outside the $CATALINA_BASE/webapps folder.

Successful exploitation of the vulnerability may allow a local attacker to obtain names of files and folder on vulnerable system.


Affected software

Oracle Linux
Amazon Linux AMI
SUSE Linux
Fedora
Apache Tomcat

JBoss Enterprise Application Platform
FlashSystem 840 9840-AE1 & 9843-AE1
Storage Copy Data Management
FlashSystem 900 9840-AE2 and 9843-AE2
SAN Volume Controller and Storwize Family
tomcat

How to mitigate CVE-2015-5174

Install the latest version Apache Tomcat 6.0.45, 7.0.65, 8.0.27

FlashSystem 840 9840-AE1 & 9843-AE1 - addressed in versions 1.3.0.6, 1.4.3.0
FlashSystem 900 9840-AE2 and 9843-AE2 - addressed in versions 1.3.0.6, 1.4.3.0
Storage Copy Data Management - update to 2.2.26.0
tomcat - addressed in versions 7.0.68-1.fc22, 7.0.68-2.fc22, 7.0.68-3.fc22, 8.0.32-3.fc23
SAN Volume Controller and Storwize Family - addressed in versions 7.5.0.8, 7.6.1.3

External References

Related Security Bulletins