===================================================================== CERT-Renater Note d'Information No. 2007/VULN339 _____________________________________________________________________ DATE : 03/08/2007 HARDWARE PLATFORM(S) : / OPERATING SYSTEM(S) : Systems running Tomcat versions 3.3 to 3.3.2. ====================================================================== CVE-2007-3384: XSS in Tomcat cookies example Severity: Low (Cross-site scripting) Vendor: The Apache Software Foundation Versions Affected: 3.3 to 3.3.2 Description: When reporting error messages, Tomcat does not filter user supplied data before display. This enables an XSS attack. Mitigation: Remove examples web application. Apply patch available from http://tomcat.apache.org/download-33.cgi Credit: This issue was discovered by Tomasz Kuczynski, Poznan Supercomputing and Networking Center, who worked with the CERT/CC to report the vulnerability. Example: http://localhost:8080/examples/servlet/CookieExample populate Name or Value field with: and submit. References: http://tomcat.apache.org/security.html ====================================================================== ========================================================= Les serveurs de référence du CERT-Renater http://www.urec.fr/securite http://www.cru.fr/securite http://www.renater.fr ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 151 bd de l'Hopital | fax : 01-53-94-20-41 + + 75013 Paris | email: certsvp@renater.fr + =========================================================