Vulnerability Description
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | >= 4.1.0, <= 4.1.39 |
Related Weaknesses (CWE)
References
- http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=127420533226623&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=129070310906557&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=136485229118404&w=2Third Party Advisory
- http://secunia.com/advisories/35685Vendor Advisory
- http://secunia.com/advisories/35788Vendor Advisory
- http://secunia.com/advisories/37460Vendor Advisory
- http://secunia.com/advisories/42368Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-263529-1Third Party Advisory
- http://support.apple.com/kb/HT4077Third Party Advisory
- http://svn.apache.org/viewvc?rev=652592&view=revPatch
- http://svn.apache.org/viewvc?rev=681156&view=revPatch
- http://svn.apache.org/viewvc?rev=739522&view=revPatch
- http://svn.apache.org/viewvc?rev=781542&view=revPatch
FAQ
What is CVE-2009-0783?
CVE-2009-0783 is a vulnerability with a CVSS score of 4.2 (MEDIUM). Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read o...
How severe is CVE-2009-0783?
CVE-2009-0783 has been rated MEDIUM with a CVSS base score of 4.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-0783?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat.