Limited directory traversal in Oracle Linux and Apache Tomcat - CVE-2015-5174
Published: August 5, 2016 / Updated: January 11, 2017
Vulnerability details
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to incorrect validation of paths in getResource(), getResourceAsStream() and getResourcePaths() methods within ServletContext. A local attacker can bypass security manager restrictions using directory traversal sequences and view directory listing outside the $CATALINA_BASE/webapps folder.
Successful exploitation of the vulnerability may allow a local attacker to obtain names of files and folder on vulnerable system.
Affected software
Amazon Linux AMI
SUSE Linux
Fedora
Apache Tomcat
JBoss Enterprise Application Platform
FlashSystem 840 9840-AE1 & 9843-AE1
Storage Copy Data Management
FlashSystem 900 9840-AE2 and 9843-AE2
SAN Volume Controller and Storwize Family
tomcat
How to mitigate CVE-2015-5174
FlashSystem 900 9840-AE2 and 9843-AE2 - addressed in versions 1.3.0.6, 1.4.3.0
Storage Copy Data Management - update to 2.2.26.0
tomcat - addressed in versions 7.0.68-1.fc22, 7.0.68-2.fc22, 7.0.68-3.fc22, 8.0.32-3.fc23
SAN Volume Controller and Storwize Family - addressed in versions 7.5.0.8, 7.6.1.3
External References
- https://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.45
- https://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.65
- https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.0.27
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
Related Security Bulletins
- Multiple vulnerabilities in Apache Tomcat
- SUSE Linux update for tomcat6
- Amazon Linux AMI update for tomcat6
- Red Hat update for jboss-ec2-eap
- Multiple vulnerabilities in IBM FlashSystem models 840 and 900
- Multiple vulnerabilities in IBM SAN Volume Controller and Storwize Family
- Fedora 23 update for tomcat
- Fedora 22 update for tomcat
- Fedora 22 update for tomcat
- Fedora 22 update for tomcat
- Multiple vulnerabilities in IBM Storage Copy Data Management