CVE Vulnerabilities

CVE-2009-2901

Published: Jan 28, 2010 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.

Affected Software

Name Vendor Start Version End Version
Tomcat Apache 5.5.0 (including) 5.5.0 (including)
Tomcat Apache 5.5.1 (including) 5.5.1 (including)
Tomcat Apache 5.5.2 (including) 5.5.2 (including)
Tomcat Apache 5.5.3 (including) 5.5.3 (including)
Tomcat Apache 5.5.4 (including) 5.5.4 (including)
Tomcat Apache 5.5.5 (including) 5.5.5 (including)
Tomcat Apache 5.5.6 (including) 5.5.6 (including)
Tomcat Apache 5.5.7 (including) 5.5.7 (including)
Tomcat Apache 5.5.8 (including) 5.5.8 (including)
Tomcat Apache 5.5.9 (including) 5.5.9 (including)
Tomcat Apache 5.5.10 (including) 5.5.10 (including)
Tomcat Apache 5.5.11 (including) 5.5.11 (including)
Tomcat Apache 5.5.12 (including) 5.5.12 (including)
Tomcat Apache 5.5.13 (including) 5.5.13 (including)
Tomcat Apache 5.5.14 (including) 5.5.14 (including)
Tomcat Apache 5.5.15 (including) 5.5.15 (including)
Tomcat Apache 5.5.16 (including) 5.5.16 (including)
Tomcat Apache 5.5.17 (including) 5.5.17 (including)
Tomcat Apache 5.5.18 (including) 5.5.18 (including)
Tomcat Apache 5.5.19 (including) 5.5.19 (including)
Tomcat Apache 5.5.20 (including) 5.5.20 (including)
Tomcat Apache 5.5.21 (including) 5.5.21 (including)
Tomcat Apache 5.5.22 (including) 5.5.22 (including)
Tomcat Apache 5.5.23 (including) 5.5.23 (including)
Tomcat Apache 5.5.24 (including) 5.5.24 (including)
Tomcat Apache 5.5.25 (including) 5.5.25 (including)
Tomcat Apache 5.5.26 (including) 5.5.26 (including)
Tomcat Apache 5.5.27 (including) 5.5.27 (including)
Tomcat Apache 5.5.28 (including) 5.5.28 (including)
Tomcat Apache 6.0 (including) 6.0 (including)
Tomcat Apache 6.0.0 (including) 6.0.0 (including)
Tomcat Apache 6.0.1 (including) 6.0.1 (including)
Tomcat Apache 6.0.2 (including) 6.0.2 (including)
Tomcat Apache 6.0.3 (including) 6.0.3 (including)
Tomcat Apache 6.0.4 (including) 6.0.4 (including)
Tomcat Apache 6.0.5 (including) 6.0.5 (including)
Tomcat Apache 6.0.6 (including) 6.0.6 (including)
Tomcat Apache 6.0.7 (including) 6.0.7 (including)
Tomcat Apache 6.0.8 (including) 6.0.8 (including)
Tomcat Apache 6.0.9 (including) 6.0.9 (including)
Tomcat Apache 6.0.10 (including) 6.0.10 (including)
Tomcat Apache 6.0.11 (including) 6.0.11 (including)
Tomcat Apache 6.0.12 (including) 6.0.12 (including)
Tomcat Apache 6.0.13 (including) 6.0.13 (including)
Tomcat Apache 6.0.14 (including) 6.0.14 (including)
Tomcat Apache 6.0.15 (including) 6.0.15 (including)
Tomcat Apache 6.0.16 (including) 6.0.16 (including)
Tomcat Apache 6.0.17 (including) 6.0.17 (including)
Tomcat Apache 6.0.18 (including) 6.0.18 (including)
Tomcat Apache 6.0.19 (including) 6.0.19 (including)
Tomcat Apache 6.0.20 (including) 6.0.20 (including)
Tomcat5 Ubuntu dapper *
Tomcat5.5 Ubuntu hardy *
Tomcat5.5 Ubuntu intrepid *
Tomcat5.5 Ubuntu jaunty *
Tomcat6 Ubuntu intrepid *
Tomcat6 Ubuntu jaunty *
Tomcat6 Ubuntu karmic *

References