CVE-2009-0783
Last modified
CVE-2009-0783 is a medium-severity vulnerability rated 4.2/10 on the CVSS scale. Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.. EPSS estimates a 0.81% chance of exploitation in the next 30 days.
Description
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.
Metrics
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | >= 4.1.0, <= 4.1.39 |
| Apache | Tomcat | >= 5.5.0, <= 5.5.27 |
| Apache | Tomcat | >= 6.0.0, <= 6.0.18 |
References
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=127420533226623&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=129070310906557&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=136485229118404&w=2Third Party Advisory
- http://secunia.com/advisories/35685Vendor Advisory
- http://secunia.com/advisories/35788Vendor Advisory
- http://secunia.com/advisories/37460Vendor Advisory
- http://secunia.com/advisories/42368Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-263529-1Third Party Advisory
- http://support.apple.com/kb/HT4077Third Party Advisory
- http://tomcat.apache.org/security-4.htmlPatch, Vendor Advisory
- http://tomcat.apache.org/security-5.htmlPatch, Vendor Advisory
- http://tomcat.apache.org/security-6.htmlPatch, Vendor Advisory
- http://www.debian.org/security/2011/dsa-2207Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:136Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:138Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:176Third Party Advisory
- http://www.securityfocus.com/archive/1/504090/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/507985/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35416Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1022336Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlThird Party Advisory
- http://www.vupen.com/english/advisories/2009/1856Vendor Advisory
- http://www.vupen.com/english/advisories/2009/3316Vendor Advisory
- http://www.vupen.com/english/advisories/2010/3056Vendor Advisory
- https://issues.apache.org/bugzilla/show_bug.cgi?id=29936Issue Tracking, Patch
- https://issues.apache.org/bugzilla/show_bug.cgi?id=45933Issue Tracking
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=127420533226623&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=129070310906557&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=136485229118404&w=2Third Party Advisory
- http://secunia.com/advisories/35685Vendor Advisory
- http://secunia.com/advisories/35788Vendor Advisory
- http://secunia.com/advisories/37460Vendor Advisory
- http://secunia.com/advisories/42368Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-263529-1Third Party Advisory
- http://support.apple.com/kb/HT4077Third Party Advisory
- http://tomcat.apache.org/security-4.htmlPatch, Vendor Advisory
- http://tomcat.apache.org/security-5.htmlPatch, Vendor Advisory
- http://tomcat.apache.org/security-6.htmlPatch, Vendor Advisory
- http://www.debian.org/security/2011/dsa-2207Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:136Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:138Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:176Third Party Advisory
- http://www.securityfocus.com/archive/1/504090/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/507985/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35416Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1022336Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlThird Party Advisory
- http://www.vupen.com/english/advisories/2009/1856Vendor Advisory
- http://www.vupen.com/english/advisories/2009/3316Vendor Advisory
- http://www.vupen.com/english/advisories/2010/3056Vendor Advisory
- https://issues.apache.org/bugzilla/show_bug.cgi?id=29936Issue Tracking, Patch
- https://issues.apache.org/bugzilla/show_bug.cgi?id=45933Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0783?
How severe is CVE-2009-0783?
How do I fix CVE-2009-0783?
Are you affected by CVE-2009-0783?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
