Bug 675786 - (CVE-2011-0013) CVE-2011-0013 tomcat: XSS vulnerability in HTML Manager interface
CVE-2011-0013 tomcat: XSS vulnerability in HTML Manager interface
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
public=20110111,reported=20110204,sou...
: Security
Depends On: 675794 675795 675923 675924 675925 675926 675931 675933 802294
Blocks:
  Show dependency treegraph
 
Reported: 2011-02-07 13:37 EST by Vincent Danen
Modified: 2016-03-04 05:41 EST (History)
13 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2011-12-20 12:45:58 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Vincent Danen 2011-02-07 13:37:02 EST
Apache Tomcat 5.5.32 and 6.0.30 were released [1],[2] to fix, among other things, an XSS vulnerability in the HTML Manager [3].  The HTML Manager displayed unfiltered web application-provided data that could be used to trigger script execution by an administrative user when viewing the Manager pages, such as:

<display-name>&lt;script&gt;alert('hi');&lt;/script&gt;</display-name> 

For Tomcat 5.5.x, this was fixed in upstream revision 1057518 [4] and for Tomcat 6.x it was fixed in upstream revision 1057270 [5].

[1] http://tomcat.apache.org/security-5.html#Fixed_in_Apache_Tomcat_5.5.32
[2] http://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.30
[3] http://archives.neohapsis.com/archives/fulldisclosure/2011-02/0077.html
[4] http://svn.apache.org/viewvc?rev=1057518&view=rev
[5] http://svn.apache.org/viewvc?rev=1057270&view=rev
Comment 1 Vincent Danen 2011-02-07 14:01:47 EST
Created tomcat6 tracking bugs for this issue

Affects: fedora-all [bug 675794]
Comment 2 Vincent Danen 2011-02-07 14:01:55 EST
Created tomcat5 tracking bugs for this issue

Affects: fedora-all [bug 675795]
Comment 5 errata-xmlrpc 2011-05-19 06:58:14 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2011:0791 https://rhn.redhat.com/errata/RHSA-2011-0791.html
Comment 6 errata-xmlrpc 2011-05-19 10:29:22 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2011:0791 https://rhn.redhat.com/errata/RHSA-2011-0791.html
Comment 7 errata-xmlrpc 2011-06-22 19:16:58 EDT
This issue has been addressed in following products:

  JBoss Enterprise Web Server 1.0

Via RHSA-2011:0896 https://rhn.redhat.com/errata/RHSA-2011-0896.html
Comment 8 errata-xmlrpc 2011-06-22 19:38:35 EDT
This issue has been addressed in following products:

  JBEWS 1.0 for RHEL 5
  JBEWS 1.0 for RHEL 4
  JBEWS 1 for RHEL 6

Via RHSA-2011:0897 https://rhn.redhat.com/errata/RHSA-2011-0897.html
Comment 10 errata-xmlrpc 2011-12-20 12:25:48 EST
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2011:1845 https://rhn.redhat.com/errata/RHSA-2011-1845.html
Comment 11 Vincent Danen 2011-12-20 12:45:58 EST
Statement:

(none)

Note You need to log in before you can comment on or make changes to this bug.