Information regarding 12085 - Apache Tomcat servlet/JSP container default files

2012-03-27 Thread Geet Chandra
Hi All, Is there any solution or workaround for protection against this security vulnerability. -Geet

Re: Information regarding 12085 - Apache Tomcat servlet/JSP container default files

2012-03-27 Thread Mark Thomas
On 27/03/2012 14:18, Geet Chandra wrote: Hi All, Is there any solution or workaround for protection against this security vulnerability. What security vulnerability is this? Every published Tomcat security vulnerability has a CVE reference to uniquely identify it. What is the CVE reference

Re: Information regarding 12085 - Apache Tomcat servlet/JSP container default files

2012-03-27 Thread Geet Chandra
Here is the CVE Reference:CVE-2002-2006 On Tue, Mar 27, 2012 at 6:51 PM, Mark Thomas ma...@apache.org wrote: On 27/03/2012 14:18, Geet Chandra wrote: Hi All, Is there any solution or workaround for protection against this security vulnerability. What security vulnerability is this?

Re: Information regarding 12085 - Apache Tomcat servlet/JSP container default files

2012-03-27 Thread Mark Thomas
On 27/03/2012 14:29, Geet Chandra wrote: Here is the CVE Reference:CVE-2002-2006 And the Tomcat version you are using? Mark On Tue, Mar 27, 2012 at 6:51 PM, Mark Thomas ma...@apache.org wrote: On 27/03/2012 14:18, Geet Chandra wrote: Hi All, Is there any solution or workaround for

Re: Information regarding 12085 - Apache Tomcat servlet/JSP container default files

2012-03-27 Thread Geet Chandra
Using Tomcat version 6.0.35 -Geet On Tue, Mar 27, 2012 at 7:02 PM, Mark Thomas ma...@apache.org wrote: On 27/03/2012 14:29, Geet Chandra wrote: Here is the CVE Reference:CVE-2002-2006 And the Tomcat version you are using? Mark On Tue, Mar 27, 2012 at 6:51 PM, Mark Thomas

Re: Information regarding 12085 - Apache Tomcat servlet/JSP container default files

2012-03-27 Thread Mark Thomas
On 27/03/2012 14:38, Geet Chandra wrote: Using Tomcat version 6.0.35 In which case go back and read the vulnerability information again and pay more attention to the part about affected versions. You should also read the Tomcat security pages. Mark -Geet On Tue, Mar 27, 2012 at 7:02

Re: Information regarding 12085 - Apache Tomcat servlet/JSP container default files

2012-03-27 Thread Geet Chandra
I found this information here http://www.westpoint.ltd.uk/example-reports/samplereport_westpoint/files/detail_493213.htm I don't see anything about affected versions. -Geet On Tue, Mar 27, 2012 at 7:20 PM, Mark Thomas ma...@apache.org wrote: On 27/03/2012 14:38, Geet Chandra wrote: Using

Re: Information regarding 12085 - Apache Tomcat servlet/JSP container default files

2012-03-27 Thread Daniel Mikusa
https://tomcat.apache.org/security-4.html#Fixed_in_Apache_Tomcat_4.1.0 or https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2006 The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive

Re: Information regarding 12085 - Apache Tomcat servlet/JSP container default files

2012-03-27 Thread Mark Thomas
Geet Chandra gee...@gmail.com wrote: I found this information here http://www.westpoint.ltd.uk/example-reports/samplereport_westpoint/files/detail_493213.htm I don't see anything about affected versions. Then try reading a proper vulnerability report rather than the output of a

Re: Information regarding 12085 - Apache Tomcat servlet/JSP container default files

2012-03-27 Thread Geet Chandra
This is what I read, now in the solution tab, it says to remove the examples folder,but we are shipping the tomcat with our product, can we remove the example folder and ship with our product.If not, any other workaround/solution.Stoplisted Vulnerabilities for this Host: 2 Vulnerability12085Apache

Re: Information regarding 12085 - Apache Tomcat servlet/JSP container default files

2012-03-27 Thread Pid
On 27/03/2012 15:28, Geet Chandra wrote: This is what I read, now in the solution tab, it says to remove the examples folder,but we are shipping the tomcat with our product, can we remove the example folder and ship with our product.If not, any other workaround/solution.Stoplisted