Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2007-5461

PUBLISHED 07.08.2024

CNA: redhat

Обновлено: 13.02.2020
Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.

EPSS

Вероятность Severity Процентиль ? Дата расчёта
6.27% LOW 91.03 23.05.2026

Exploits & Shellcodes

Идентификатор Тип Описание Дата публикации
EDB-4552 Exploit Apache Tomcat - WebDAV SSL Remote File Disclosure 21.10.2007
EDB-4530 Exploit Apache Tomcat - 'WebDAV' Remote File Disclosure 14.10.2007

Доп. Информация

Product Status

n/a
Product: n/a
Vendor: n/a
Default status: Не определен
Версии:
Затронутые версии Статус
Наблюдалось в версии n/a affected
 

Ссылки

http://www.debian.org/security/2008/dsa-1453
http://tomcat.apache.org/security-4.html
http://secunia.com/advisories/30908
http://support.apple.com/kb/HT2163
http://mail-archives.apache.org/mod_mbox/tomcat-users/200710.mbox/%3C47135C2D.1000705%40apache.org%3E
http://www.securityfocus.com/bid/26070
http://secunia.com/advisories/27446
http://marc.info/?l=full-disclosure&m=119239530508382
http://secunia.com/advisories/30676
http://rhn.redhat.com/errata/RHSA-2008-0630.html
http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1
https://exchange.xforce.ibmcloud.com/vulnerabilities/37243
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9202
http://www.redhat.com/support/errata/RHSA-2008-0862.html
http://www.vupen.com/english/advisories/2008/1981/references
http://secunia.com/advisories/30899
https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00525.html
http://secunia.com/advisories/31493
http://secunia.com/advisories/29242
http://www.vupen.com/english/advisories/2008/2823
http://secunia.com/advisories/37460
http://www.vupen.com/english/advisories/2008/1979/references
http://secunia.com/advisories/29313
http://www.securityfocus.com/bid/31681
http://secunia.com/advisories/32120
http://www.vupen.com/english/advisories/2007/3671
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
http://secunia.com/advisories/27398
http://www.redhat.com/support/errata/RHSA-2008-0042.html
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html
http://www.securitytracker.com/id?1018864
http://secunia.com/advisories/28361
http://secunia.com/advisories/28317
http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html
http://support.avaya.com/elmodocs2/security/ASA-2008-401.htm
http://www.vupen.com/english/advisories/2007/3674
http://www.securityfocus.com/archive/1/507985/100/0/threaded
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
http://tomcat.apache.org/security-6.html
http://secunia.com/advisories/57126
http://secunia.com/advisories/32222
http://secunia.com/advisories/30802
http://www.redhat.com/support/errata/RHSA-2008-0195.html
http://security.gentoo.org/glsa/glsa-200804-10.xml
http://geronimo.apache.org/2007/10/18/potential-vulnerability-in-apache-tomcat-webdav-servlet.html
http://www.vupen.com/english/advisories/2007/3622
http://www-1.ibm.com/support/docview.wss?uid=swg21286112
http://secunia.com/advisories/27727
http://www.vupen.com/english/advisories/2008/1856/references
http://www.vmware.com/security/advisories/VMSA-2008-0010.html
http://tomcat.apache.org/security-5.html
http://www.vupen.com/english/advisories/2008/2780
http://www.redhat.com/support/errata/RHSA-2008-0261.html
https://www.exploit-db.com/exploits/4530
http://www.mandriva.com/security/advisories?name=MDVSA-2009:136
http://www.debian.org/security/2008/dsa-1447
http://secunia.com/advisories/27481
http://marc.info/?l=bugtraq&m=139344343412337&w=2
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
http://support.apple.com/kb/HT3216
http://www.mandriva.com/security/advisories?name=MDKSA-2007:241
http://secunia.com/advisories/29711
http://issues.apache.org/jira/browse/GERONIMO-3549
http://www.vupen.com/english/advisories/2009/3316
http://secunia.com/advisories/32266
https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org...
https://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org...
https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org...
https://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org...
https://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.or...
https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.or...
https://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.or...

CVE Program Container

Обновлено: 07.08.2024
SSVC and KEV, plus CVSS and CWE if not provided by the CNA.

Ссылки

http://www.debian.org/security/2008/dsa-1453
http://tomcat.apache.org/security-4.html
http://secunia.com/advisories/30908
http://support.apple.com/kb/HT2163
http://mail-archives.apache.org/mod_mbox/tomcat-users/200710.mbox/%3C47135C2D.1000705%40apache.org%3E
http://www.securityfocus.com/bid/26070
http://secunia.com/advisories/27446
http://marc.info/?l=full-disclosure&m=119239530508382
http://secunia.com/advisories/30676
http://rhn.redhat.com/errata/RHSA-2008-0630.html
http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1
https://exchange.xforce.ibmcloud.com/vulnerabilities/37243
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9202
http://www.redhat.com/support/errata/RHSA-2008-0862.html
http://www.vupen.com/english/advisories/2008/1981/references
http://secunia.com/advisories/30899
https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00525.html
http://secunia.com/advisories/31493
http://secunia.com/advisories/29242
http://www.vupen.com/english/advisories/2008/2823
http://secunia.com/advisories/37460
http://www.vupen.com/english/advisories/2008/1979/references
http://secunia.com/advisories/29313
http://www.securityfocus.com/bid/31681
http://secunia.com/advisories/32120
http://www.vupen.com/english/advisories/2007/3671
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
http://secunia.com/advisories/27398
http://www.redhat.com/support/errata/RHSA-2008-0042.html
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html
http://www.securitytracker.com/id?1018864
http://secunia.com/advisories/28361
http://secunia.com/advisories/28317
http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html
http://support.avaya.com/elmodocs2/security/ASA-2008-401.htm
http://www.vupen.com/english/advisories/2007/3674
http://www.securityfocus.com/archive/1/507985/100/0/threaded
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
http://tomcat.apache.org/security-6.html
http://secunia.com/advisories/57126
http://secunia.com/advisories/32222
http://secunia.com/advisories/30802
http://www.redhat.com/support/errata/RHSA-2008-0195.html
http://security.gentoo.org/glsa/glsa-200804-10.xml
http://geronimo.apache.org/2007/10/18/potential-vulnerability-in-apache-tomcat-webdav-servlet.html
http://www.vupen.com/english/advisories/2007/3622
http://www-1.ibm.com/support/docview.wss?uid=swg21286112
http://secunia.com/advisories/27727
http://www.vupen.com/english/advisories/2008/1856/references
http://www.vmware.com/security/advisories/VMSA-2008-0010.html
http://tomcat.apache.org/security-5.html
http://www.vupen.com/english/advisories/2008/2780
http://www.redhat.com/support/errata/RHSA-2008-0261.html
https://www.exploit-db.com/exploits/4530
http://www.mandriva.com/security/advisories?name=MDVSA-2009:136
http://www.debian.org/security/2008/dsa-1447
http://secunia.com/advisories/27481
http://marc.info/?l=bugtraq&m=139344343412337&w=2
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
http://support.apple.com/kb/HT3216
http://www.mandriva.com/security/advisories?name=MDKSA-2007:241
http://secunia.com/advisories/29711
http://issues.apache.org/jira/browse/GERONIMO-3549
http://www.vupen.com/english/advisories/2009/3316
http://secunia.com/advisories/32266
https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org...
https://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org...
https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org...
https://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org...
https://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.or...
https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.or...
https://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.or...

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.