Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.
References
Link Providers
http://geronimo.apache.org/2007/10/18/potential-vulnerability-in-apache-tomcat-webdav-servlet.html cve-icon cve-icon
http://issues.apache.org/jira/browse/GERONIMO-3549 cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html cve-icon cve-icon
http://mail-archives.apache.org/mod_mbox/tomcat-users/200710.mbox/%3C47135C2D.1000705%40apache.org%3E cve-icon cve-icon
http://marc.info/?l=bugtraq&m=139344343412337&w=2 cve-icon cve-icon
http://marc.info/?l=full-disclosure&m=119239530508382 cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2008-0630.html cve-icon cve-icon
http://secunia.com/advisories/27398 cve-icon cve-icon
http://secunia.com/advisories/27446 cve-icon cve-icon
http://secunia.com/advisories/27481 cve-icon cve-icon
http://secunia.com/advisories/27727 cve-icon cve-icon
http://secunia.com/advisories/28317 cve-icon cve-icon
http://secunia.com/advisories/28361 cve-icon cve-icon
http://secunia.com/advisories/29242 cve-icon cve-icon
http://secunia.com/advisories/29313 cve-icon cve-icon
http://secunia.com/advisories/29711 cve-icon cve-icon
http://secunia.com/advisories/30676 cve-icon cve-icon
http://secunia.com/advisories/30802 cve-icon cve-icon
http://secunia.com/advisories/30899 cve-icon cve-icon
http://secunia.com/advisories/30908 cve-icon cve-icon
http://secunia.com/advisories/31493 cve-icon cve-icon
http://secunia.com/advisories/32120 cve-icon cve-icon
http://secunia.com/advisories/32222 cve-icon cve-icon
http://secunia.com/advisories/32266 cve-icon cve-icon
http://secunia.com/advisories/37460 cve-icon cve-icon
http://secunia.com/advisories/57126 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200804-10.xml cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1 cve-icon cve-icon
http://support.apple.com/kb/HT2163 cve-icon cve-icon
http://support.apple.com/kb/HT3216 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2008-401.htm cve-icon cve-icon
http://tomcat.apache.org/security-4.html cve-icon cve-icon
http://tomcat.apache.org/security-5.html cve-icon cve-icon
http://tomcat.apache.org/security-6.html cve-icon cve-icon
http://www-1.ibm.com/support/docview.wss?uid=swg21286112 cve-icon cve-icon
http://www.debian.org/security/2008/dsa-1447 cve-icon cve-icon
http://www.debian.org/security/2008/dsa-1453 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:241 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2009:136 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0042.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0195.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0261.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0862.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/507985/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/26070 cve-icon cve-icon
http://www.securityfocus.com/bid/31681 cve-icon cve-icon
http://www.securitytracker.com/id?1018864 cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2008-0010.html cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2009-0016.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3622 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3671 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3674 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1856/references cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1979/references cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1981/references cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2780 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2823 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/3316 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/37243 cve-icon cve-icon
https://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-5461 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9202 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-5461 cve-icon
https://www.exploit-db.com/exploits/4530 cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00525.html cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2007-10-15T18:00:00

Updated: 2024-08-07T15:31:58.669Z

Reserved: 2007-10-15T00:00:00

Link: CVE-2007-5461

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-10-15T18:17:00.000

Modified: 2023-11-07T02:01:18.920

Link: CVE-2007-5461

cve-icon Redhat

Severity : Important

Publid Date: 2007-10-14T00:00:00Z

Links: CVE-2007-5461 - Bugzilla