CVE Vulnerabilities

CVE-2007-5342

Published: Dec 27, 2007 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.

Affected Software

Name Vendor Start Version End Version
Tomcat Apache 5.5.9 (including) 5.5.9 (including)
Tomcat Apache 5.5.10 (including) 5.5.10 (including)
Tomcat Apache 5.5.11 (including) 5.5.11 (including)
Tomcat Apache 5.5.12 (including) 5.5.12 (including)
Tomcat Apache 5.5.13 (including) 5.5.13 (including)
Tomcat Apache 5.5.14 (including) 5.5.14 (including)
Tomcat Apache 5.5.15 (including) 5.5.15 (including)
Tomcat Apache 5.5.16 (including) 5.5.16 (including)
Tomcat Apache 5.5.17 (including) 5.5.17 (including)
Tomcat Apache 5.5.18 (including) 5.5.18 (including)
Tomcat Apache 5.5.19 (including) 5.5.19 (including)
Tomcat Apache 5.5.20 (including) 5.5.20 (including)
Tomcat Apache 5.5.21 (including) 5.5.21 (including)
Tomcat Apache 5.5.22 (including) 5.5.22 (including)
Tomcat Apache 5.5.23 (including) 5.5.23 (including)
Tomcat Apache 5.5.24 (including) 5.5.24 (including)
Tomcat Apache 5.5.25 (including) 5.5.25 (including)
Tomcat Apache 6.0 (including) 6.0 (including)
Tomcat Apache 6.0.1 (including) 6.0.1 (including)
Tomcat Apache 6.0.2 (including) 6.0.2 (including)
Tomcat Apache 6.0.3 (including) 6.0.3 (including)
Tomcat Apache 6.0.4 (including) 6.0.4 (including)
Tomcat Apache 6.0.5 (including) 6.0.5 (including)
Tomcat Apache 6.0.6 (including) 6.0.6 (including)
Tomcat Apache 6.0.7 (including) 6.0.7 (including)
Tomcat Apache 6.0.8 (including) 6.0.8 (including)
Tomcat Apache 6.0.9 (including) 6.0.9 (including)
Tomcat Apache 6.0.10 (including) 6.0.10 (including)
Tomcat Apache 6.0.11 (including) 6.0.11 (including)
Tomcat Apache 6.0.12 (including) 6.0.12 (including)
Tomcat Apache 6.0.13 (including) 6.0.13 (including)
Tomcat Apache 6.0.14 (including) 6.0.14 (including)
Tomcat Apache 6.0.15 (including) 6.0.15 (including)
JBEAP 4.2.0 for RHEL 4 RedHat glassfish-javamail-0:1.4.0-0jpp.ep1.10.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat hibernate3-1:3.2.4-1.SP1_CP04.0jpp.ep1.3.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat hibernate3-annotations-0:3.2.1-4.GA_CP02.1jpp.ep1.7.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat hibernate3-validator-0:0.0.0-1.1jpp.ep1.1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jboss-aop-0:1.5.5-2.CP02.0jpp.ep1.2.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jbossas-0:4.2.0-3.GA_CP04.ep1.8.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jboss-remoting-0:2.2.2-3.SP9.0jpp.ep1.1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jboss-seam-0:1.2.1-1.ep1.10.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jbossts-1:4.2.3-1.SP5_CP02.1jpp.ep1.1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jbossweb-0:2.0.0-4.CP06.0jpp.ep1.1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat rh-eap-docs-0:4.2.0-4.GA_CP04.ep1.5.el4 *
JBEAP 4.2.0 for RHEL 5 RedHat hibernate3-1:3.2.4-1.SP1_CP04.0jpp.ep1.3.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat hibernate3-annotations-0:3.2.1-4.GA_CP02.1jpp.ep1.7.el5.1 *
JBEAP 4.2.0 for RHEL 5 RedHat jboss-aop-0:1.5.5-2.CP02.0jpp.ep1.2.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jbossas-0:4.2.0-4.GA_CP04.ep1.7.el5.6 *
JBEAP 4.2.0 for RHEL 5 RedHat jboss-remoting-0:2.2.2-3.SP9.0jpp.ep1.2.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jboss-seam-0:1.2.1-1.ep1.9.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jbossts-1:4.2.3-1.SP5_CP02.1jpp.ep1.2.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jbossweb-0:2.0.0-4.CP06.0jpp.ep1.1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat rh-eap-docs-0:4.2.0-4.GA_CP04.ep1.3.el5 *
Red Hat Developer Suite V.3 RedHat tomcat5-0:5.5.23-0jpp_11rh *
Red Hat Enterprise Linux 5 RedHat tomcat5-0:5.5.23-0jpp.3.0.3.el5_1 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat glassfish-javamail-0:1.4.0-0jpp.ep1.10.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat glassfish-jaxb-0:2.1.4-1jpp.ep1.2.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat glassfish-jaxws-0:2.1.1-1jpp.ep1.3.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat hibernate3-1:3.2.4-1.SP1_CP04.0jpp.ep1.3.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat hibernate3-annotations-0:3.2.1-4.GA_CP02.1jpp.ep1.7.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat hibernate3-validator-0:0.0.0-1.1jpp.ep1.1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat javassist-0:3.8.0-1.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-aop-0:1.5.5-2.CP02.0jpp.ep1.2.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossas-0:4.3.0-2.GA_CP02.ep1.10.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-messaging-0:1.4.0-1.SP3_CP03.0jpp.ep1.3.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-remoting-0:2.2.2-3.SP9.0jpp.ep1.1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.10.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossts-1:4.2.3-1.SP5_CP02.1jpp.ep1.1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossweb-0:2.0.0-4.CP06.0jpp.ep1.1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossws-0:2.0.1-2.SP2_CP03.0jpp.ep1.1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossws-common-0:1.0.0-1.GA_CP01.0jpp.ep1.3.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossws-framework-0:2.0.1-0jpp.ep1.11.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat rh-eap-docs-0:4.3.0-3.GA_CP02.ep1.9.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat glassfish-jaf-0:1.1.0-0jpp.ep1.12.el5.1 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat glassfish-javamail-0:1.4.0-0jpp.ep1.10.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat glassfish-jaxb-0:2.1.4-1jpp.ep1.4.el5.2 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat glassfish-jaxws-0:2.1.1-1jpp.ep1.3.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat glassfish-jstl-0:1.2.0-0jpp.ep1.10.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat hibernate3-1:3.2.4-1.SP1_CP04.0jpp.ep1.3.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat hibernate3-annotations-0:3.2.1-4.GA_CP02.1jpp.ep1.7.el5.1 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat hibernate3-commons-annotations-0:0.0.0-1.1jpp.ep1.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat hibernate3-entitymanager-0:3.2.1-2.GA_CP03.1jpp.ep1.9.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat hibernate3-validator-0:0.0.0-1.1jpp.ep1.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat javassist-0:3.8.0-1jpp.ep1.2.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-aop-0:1.5.5-2.CP02.0jpp.ep1.2.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossas-0:4.3.0-2.GA_CP02.ep1.10.el5.2 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-jaxr-0:1.2.0-SP1.0jpp.ep1.4.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-messaging-0:1.4.0-1.SP3_CP03.0jpp.ep1.3.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-remoting-0:2.2.2-3.SP9.0jpp.ep1.2.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.7.el5.1 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossts-1:4.2.3-1.SP5_CP02.1jpp.ep1.2.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossweb-0:2.0.0-4.CP06.0jpp.ep1.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossws-0:2.0.1-2.SP2_CP03.0jpp.ep1.1.el5.1 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossws-common-0:1.0.0-1.GA_CP01.0jpp.ep1.3.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossws-framework-0:2.0.1-0jpp.ep1.11.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossxb-0:1.0.0-2.SP3.0jpp.ep1.3.el5.1 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat rh-eap-docs-0:4.3.0-2.GA_CP02.ep1.6.el5 *
RHAPS Version 2 for RHEL 4 RedHat tomcat5-0:5.5.23-0jpp_4rh.9 *
Tomcat5.5 Ubuntu devel *
Tomcat5.5 Ubuntu edgy *
Tomcat5.5 Ubuntu feisty *
Tomcat5.5 Ubuntu gutsy *
Tomcat5.5 Ubuntu hardy *
Tomcat5.5 Ubuntu intrepid *

References