Vulnerability Description
mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat Jk Web Server Connector | <= 1.2.22 |
Related Weaknesses (CWE)
References
- http://docs.info.apple.com/article.html?artnum=306172
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795
- http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html
- http://secunia.com/advisories/25383PatchVendor Advisory
- http://secunia.com/advisories/25701Vendor Advisory
- http://secunia.com/advisories/26235Vendor Advisory
- http://secunia.com/advisories/26512Vendor Advisory
- http://secunia.com/advisories/27037Vendor Advisory
- http://secunia.com/advisories/29242Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200708-15.xml
- http://tomcat.apache.org/connectors-doc/news/20070301.html#20070518.1Patch
- http://tomcat.apache.org/security-jk.htmlPatch
- http://www.debian.org/security/2007/dsa-1312
- http://www.osvdb.org/34877
FAQ
What is CVE-2007-1860?
CVE-2007-1860 is a vulnerability with a CVSS score of 5.0 (MEDIUM). mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protect...
How severe is CVE-2007-1860?
CVE-2007-1860 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-1860?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat Jk Web Server Connector.