'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2017-12616: Apache Tomcat Source Code Leak Vulnerability
Severity:high
CVE ID:CVE-2017-12616
| Descripiton:
|
Apache Tomcat is a lightweight web application server of the Jakarta project under the Apache Software Foundation. It is mainly used to develop and debug JSP programs and is suitable for small and medium-sized systems. There are security vulnerabilities in Apache Tomcat 7.0.0 to 7.0.80. When Tomcat uses VirtualDirContext, an attacker can use the vulnerability to bypass security restrictions with a specially crafted request, and view the JSPs source code of the resources provided by VirtualDirContext. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.