Summary
Requesting the URI /caucho-status gives information about the currently running Resin java servlet container.
Solution
If you don't use this feature, set the content of the '<caucho-status>' element to 'false' in the resin.conf file.
Severity
Classification
-
CVSS Base Score: 7.8
AV:N/AC:L/Au:N/C:N/I:N/A:C
Related Vulnerabilities
- Adobe AIR Security Bypass Vulnerability Jan14 (Windows)
- Adobe Flash Player Code Execution and DoS Vulnerabilities (Linux)
- Adobe AIR Code Execution and DoS Vulnerabilities Nov13 (Mac OS X)
- Adobe Acrobat and Reader Multiple Vulnerabilities -July10 (Windows)
- Adobe AIR Multiple Vulnerabilities(APSB14-22)-(Mac OS X)