Korean
<< Back
VID 22505
Severity 30
Port 80, ...
Protocol TCP
Class WWW
Detailed Description The remote Apache Tomcat install is affected by an information disclosure vulnerability which allows JSP source code to be sent as a response to an HTTP request that does not end with an HTTP protocol specification.

* Note: This check solely relied on the version number of the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://tomcat.apache.org/security-4.html#Fixed_in_Apache_Tomcat_3.2.2
https://issues.apache.org/bugzilla/show_bug.cgi?id=748

* Platforms Affected:
Apache Tomcat versions prior to 3.2.2
Any operating system Any version
Recommendation Upgrade to the latest version of Apache Tomcat Server (3.2.2 or later), available from the Apache Software Foundation download site, http://tomcat.apache.org/
Related URL CVE-2001-0590 (CVE)
Related URL 2518 (SecurityFocus)
Related URL (ISS)