Summary
This host is running Apache Tomcat and is prone to multiple vulnerabilities.
Impact
Successful exploitation will allow remote attackers to conduct session fixation attacks and manipulate certain data.
Impact Level: Application
Solution
Upgrade to version 6.0.39 or 7.0.47 or 8.0.0-RC3 or later, For Updates refer to http://tomcat.apache.org
Insight
Flaws are due to the HTTP connector or AJP connector which do not properly handle certain inconsistent HTTP request headers.
Affected
Apache Tomcat version before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3
Detection
Get the installed version of Apache Tomcat with the help of detect NVT and check the version is vulnerable or not.
References
Severity
Classification
-
CVE CVE-2013-4286 -
CVSS Base Score: 5.8
AV:N/AC:M/Au:N/C:P/I:P/A:N
Related Vulnerabilities
- Apple iTunes Tutorials Window Security Bypass Vulnerability (Windows)
- Apple Safari 'background' Remote Denial Of Service Vulnerability
- Adobe Reader Cross-Site Scripting & Denial of Service Vulnerabilities (Windows)
- Brother HL-5370DW Printer 'post/panel.html' Security Bypass Vulnerability
- Adobe Reader Cross-Site Scripting & Denial of Service Vulnerabilities (Linux)