A web application was able to replace the XML parser used by Tomcat to process web.xml, context.xml and tld files. In limited circumstances these bugs may allow a rouge web application to view and/or alter the web.xml, context.xml and tld files of other web applications deployed on the Tomcat instance. Fixes for tomcat5: http://svn.apache.org/viewvc?rev=681156&view=rev http://svn.apache.org/viewvc?rev=781542&view=rev Fixes for tomcat6: http://svn.apache.org/viewvc?rev=652592&view=rev http://svn.apache.org/viewvc?rev=739522&view=rev
This issue has been addressed in following products: JBEAP 4.3.0 for RHEL 5 Via RHSA-2009:1145 https://rhn.redhat.com/errata/RHSA-2009-1145.html
This issue has been addressed in following products: JBEAP 4.3.0 for RHEL 4 Via RHSA-2009:1146 https://rhn.redhat.com/errata/RHSA-2009-1146.html
This issue has been addressed in following products: JBEAP 4.2.0 for RHEL 5 Via RHSA-2009:1143 https://rhn.redhat.com/errata/RHSA-2009-1143.html
This issue has been addressed in following products: JBEAP 4.2.0 for RHEL 4 Via RHSA-2009:1144 https://rhn.redhat.com/errata/RHSA-2009-1144.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2009:1164 https://rhn.redhat.com/errata/RHSA-2009-1164.html
This issue has been addressed in following products: JBEWS 1.0.0 for RHEL 4 JBEWS 1.0.0 for RHEL 5 Via RHSA-2009:1454 https://rhn.redhat.com/errata/RHSA-2009-1454.html
This issue has been addressed in following products: JBEWS 1.0.0 for RHEL 5 JBEWS 1.0.0 for RHEL 4 Via RHSA-2009:1506 https://rhn.redhat.com/errata/RHSA-2009-1506.html
This issue has been addressed in following products: RHAPS Version 2 for RHEL 4 Via RHSA-2009:1562 https://rhn.redhat.com/errata/RHSA-2009-1562.html
This issue has been addressed in following products: Red Hat Developer Suite V.3 Via RHSA-2009:1563 https://rhn.redhat.com/errata/RHSA-2009-1563.html
This issue has been addressed in following products: Red Hat Network Satellite Server v 5.2 Red Hat Network Satellite Server v 5.3 Via RHSA-2009:1616 https://rhn.redhat.com/errata/RHSA-2009-1616.html
This issue has been addressed in following products: Red Hat Network Satellite Server v 5.1 Via RHSA-2009:1617 https://rhn.redhat.com/errata/RHSA-2009-1617.html
All children bugs are closed, closing parent bug