CVE-2010-3718
tomcat6 - several
EPSS 1.4%
描述
Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.
如何修補 CVE-2010-3718
要修補 CVE-2010-3718,請將受影響套件升級到下列已修補版本。
- Debian/tomcat6—升級至 6.0.28-9+squeeze1 或更新版本
- Maven/org.apache.tomcat:tomcat—升級至 7.0.4 或更新版本
CVE-2010-3718 正在被利用嗎?
低 — EPSS 為 1.4%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 6.0.28-9+squeeze1
- >= 7.0.0, < 7.0.4