MEDIUM · 5.0

CVE-2007-5366

The Tomcat 4.1-based Servlet Service in Fujitsu Interstage Application Server 7.0 through 9.0.0 and Interstage Apworks/Studio 7.0 through 9.0.0 allows remote attackers to obtain sensitive information ...

Vulnerability Description

The Tomcat 4.1-based Servlet Service in Fujitsu Interstage Application Server 7.0 through 9.0.0 and Interstage Apworks/Studio 7.0 through 9.0.0 allows remote attackers to obtain sensitive information (web root path) via unspecified vectors that trigger an error message, probably related to enabling the useCanonCaches Java Virtual Machine (JVM) option.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
FujitsuInterstage Application Server7.0
FujitsuInterstage Apworks7.0
FujitsuInterstage Studio8.01

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-5366?

CVE-2007-5366 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Tomcat 4.1-based Servlet Service in Fujitsu Interstage Application Server 7.0 through 9.0.0 and Interstage Apworks/Studio 7.0 through 9.0.0 allows remote attackers to obtain sensitive information ...

How severe is CVE-2007-5366?

CVE-2007-5366 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-5366?

Check the references section above for vendor advisories and patch information. Affected products include: Fujitsu Interstage Application Server, Fujitsu Interstage Apworks, Fujitsu Interstage Studio.