CVE-2008-2370

Impact:
Important
Public Date:
2008-08-01
Bugzilla:
457934: CVE-2008-2370 tomcat RequestDispatcher information disclosure vulnerability

The MITRE CVE dictionary describes this issue as:

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.

Find out more about CVE-2008-2370 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Enterprise Application Platform 4.3.0 for RHEL 5 Server (jbossweb) RHSA-2008:0877 2008-09-22
Red Hat Certificate System 7.3 for 4AS RHSA-2010:0602 2010-08-04
Red Hat Enterprise Linux 5 (tomcat5) RHSA-2008:0648 2008-08-27
Red Hat JBoss Enterprise Application Platform 4.2.0 for RHEL 5 Server (jbossweb) RHSA-2008:0877 2008-09-22
Red Hat Application Server v2 4AS (tomcat5) RHSA-2008:0862 2008-10-02
Red Hat Satellite 5.0 (RHEL v.4 AS) RHSA-2008:1007 2008-12-08
Red Hat Satellite 5.1 (RHEL v.4 AS) (tomcat5) RHSA-2008:1007 2008-12-08
Red Hat Developer Suite v.3 (AS v.4) (tomcat5) RHSA-2008:0864 2008-10-02
Red Hat JBoss Enterprise Application Platform 4.3.0 for RHEL 4 AS (jbossweb) RHSA-2008:0877 2008-09-22
Red Hat JBoss Enterprise Application Platform 4.2.0 for RHEL 4 AS (jbossweb) RHSA-2008:0877 2008-09-22

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.