CERT-In Advisory
CIAD-2012-0056
Multiple Vulnerabilities in Apache Tomcat Web Server
Original Issue Date: December 27, 2012
Severity Rating: High
Systems Affected
- Apache Tomcat 6.x prior to 6.0.36
- Apache Tomcat 7.x prior to 7.0.32
Overview
Multiple vulnerabilities have been reported in Apache Tomcat which could be exploited by remote attacker to conduct cross-site request forgery or denial of service attacks.
Description
1. Denial of Service Vulnerability
(
CVE-2012-4534
)
This vulnerability exists in the Apache Tomcat Systems which are using the NIO connector with sendfile and HTTPS enabled . A remote attacker could exploit this vulnerability while reading the response when a large static file is requested. Successful exploitation of this vulnerability can lead the target system to enter an infinite loop and can cause denial-of-service conditions.
2. CSRF filter Bypass Vulnerability
(
CVE-2012-4531
)
This vulnerability is exploited in ¿org/apache/catalina/filters/CsrfPreventionFilter¿in Apache Tomcat. An unauthenticated, remote attacker could exploit this vulnerability to bypass the CSRF Prevention Filter by sending a specially crafted request to a protected resource without a session identifier present in the request. The attacker can afterwards perform certain actions in the context of an authorized user and gain access to the affected application.
3. Security Bypass Vulnerability
(
CVE-2012-3546
)
This vulnerability is triggered during FORM authentication when handling a request that has been apended with /j_security_check. A remote attacker could exploit this vulnerability to bypass the security constraint checks by leveraging a previous ¿setUserPrincipal¿ call and then placing ¿/j_security_check¿ at the end of a URI.
Solution
Upgrade to the latest version (6.0.36, 7.0.32) or later
http://tomcat.apache.org/security.html
Vendor Information
Apache
http://tomcat.apache.org/security-7.html
http://tomcat.apache.org/security-6.html
References
Apache
http://tomcat.apache.org/security-7.html
http://tomcat.apache.org/security-6.html
Security Tracker
http://securitytracker.com/id/1027836
http://securitytracker.com/id/1027834
http://securitytracker.com/id/1027833
Security focus
http://www.securityfocus.com/bid/56812
http://www.securityfocus.com/bid/56813
http://www.securityfocus.com/bid/56814
CVE Name
CVE-2012-4534
CVE-2012-3546
CVE-2012-4431
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|