27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Apache Tomcat /status Information Disclosure<br />

<strong>PVS</strong> ID: 1462 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:11218<br />

Description: Synopsis :\n\nThe remote host may give an attacker information useful for future<br />

attacks.\n\nThe remote host is running the Tomcat web server, with the /status special page<br />

set. By requesting this URI, an attacker may obtain information about the status of the<br />

remote host and may also be able to reset the statistics of the server.<br />

Solution: If you do not use this feature, comment out the appropriate section in your httpd.conf file. If<br />

you really need it, limit access to the administrator's host.<br />

CVE Not available<br />

Apache Tomcat < 4.x JSP Source Code Disclosure<br />

<strong>PVS</strong> ID: 1463 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:11176<br />

Description: Synopsis :\n\nThe remote web server can disclose source code.\n\nTomcat 4.0.4 and 4.1.10<br />

(and possibly earlier versions) are vulnerable to source code disclosure by using the default<br />

servlet org.apache.catalina.servlets.DefaultServlet<br />

Solution: Upgrade to version 4.0.5, 4.1.12 or higher<br />

CVE-2002-1148<br />

Apache Tomcat Snoop Servlet Remote Information Disclosure<br />

<strong>PVS</strong> ID: 1464 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:10478<br />

Description: Synopsis :\n\nThe remote host may give an attacker information useful for future<br />

attacks.\n\nThe remote Tomcat server has the 'snoop' servlet installed. This servlet<br />

discloses valuable information about the remote host, such as the server type and version,<br />

the PATHs in use, and the kernel version of the remote host. An attacker may use this<br />

information to gain intimate knowledge about this host and make more precise attacks<br />

against it.<br />

Solution: Delete this servlet<br />

CVE-2000-0760<br />

Jakarta Tomcat < 3.2.1 Path Disclosure<br />

<strong>PVS</strong> ID: 1465 FAMILY: Web Servers<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:10807<br />

Family Internet Services 377

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!