[SECURITY] CVE-2008-5515 RequestDispatcher directory traversal vulnerability

2009-06-08 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2008-5515: Apache Tomcat information disclosure vulnerability Severity: Important Vendor: The Apache Software Foundation Versions Affected: Tomcat 4.1.0 to 4.1.39 Tomcat 5.5.0 to 5.5.27 Tomcat 6.0.0 to 6.0.18 The unsupported Tomcat 3.x, 4.0.x an

Help on upgrade tomcat bundled with JBoss for resolving tomcat security issue -[SECURITY] CVE-2008-5515 RequestDispatcher directory traversal vulnerability

2010-10-25 Thread wwtfu
Dear Sir/Madam, Recently it has been checked that there is security vulnerability for the tomcat (version 5.0.9) shipped with the JBoss 4.0.3SP1. >From the link below, it is recommended to upgrade to 5.5.28. http://marc.info/?l=tomcat-user&m=124449799021571&w=2 We have tried to upgrade the

Re: Help on upgrade tomcat bundled with JBoss for resolving tomcat security issue -[SECURITY] CVE-2008-5515 RequestDispatcher directory traversal vulnerability

2010-10-25 Thread wwtfu
Yes. Thanks & regards, Wilson Fu Tel: 3182 6675 ww...@ogcio.gov.hk 26.10.2010 10:42 Please respond to "Tomcat Users List" To users@tomcat.apache.org cc Subject Help on upgrade tomcat bundled with JBoss for resolving tomcat security issue -[SECURITY] CVE-2008-5515 Req

Re: Help on upgrade tomcat bundled with JBoss for resolving tomcat security issue -[SECURITY] CVE-2008-5515 RequestDispatcher directory traversal vulnerability

2010-10-30 Thread Pid
On 26/10/2010 03:42, ww...@ogcio.gov.hk wrote: > > Dear Sir/Madam, > > Recently it has been checked that there is security vulnerability for > the tomcat (version 5.0.9) shipped with the JBoss 4.0.3SP1. > > From the link below, it is recommended to upgrade to 5.5.28. > > http://marc.info/?l=tom