Upstream information
Description
Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preceding a filename with a mapped extension, as demonstrated by URLs ending with /;index.jsp and /;help.do.NVD CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Novell/SUSE information
Novell Bugzilla entry: 194425, 472884 SUSE Security Advisories:- SUSE-SR:2009:004, published Tue, 17 Feb 2009 10:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| Novell Linux Desktop 9 SDK for x86 Novell Linux Desktop 9 SDK for x86_64 |
| core9.x86 sles9-nlpos.x86 sles9-nld.x86-64 core9.ia64 core9.s390x core9.x86-64 sles9-oes.x86 core9.ppc core9.s390 sles9-nld.x86 YOU Patch Nr: 12343 |
| Open Enterprise Server |
| core9.x86 sles9-nlpos.x86 sles9-nld.x86-64 core9.ia64 core9.s390x core9.x86-64 sles9-oes.x86 core9.ppc core9.s390 sles9-nld.x86 YOU Patch Nr: 12343 |
| SUSE Linux Enterprise SDK 10 SP2 |
| sles10-sp2.ppc sle10-sp2-sdk.x86-64 sles10-sp2.x86-64 sle10-sp2-sdk.x86 sle10-sp2-sdk.ia64 sles10-sp2.ia64 sle10-sp2-sdk.ppc sle10-sp2-sdk.s390x sles10-sp2.s390x sles10-sp2.x86 ZYPP Patch Nr: 5955 |
