Bugtraq has had reports that Tomcat has vulnerabilities that allow remote users to get paths and to compromise root if Tomcat is run as root. Are these true?
Location: http://www.jguru.com/faq/view.jsp?EID=131224 Created: Aug 21, 2000 Modified: 2000-08-21 19:02:58.72 Author: Ignacio J. Ortega (http://www.jguru.com/guru/viewbio.jsp?EID=98626) Question originally posed by zeno godofnothin (http://www.jguru.com/guru/viewbio.jsp?EID=117406 Yes, for Tomcat 3.1. No, for Tomcat 3.2 Beta. But is very easy to secure Tomcat 3.1: • Stop Tomcat • delete the contents of %TOMCAT_HOME%/work • Delete the file: admin.
Related Questions
- Bugtraq has had reports that Tomcat has vulnerabilities that allow remote users to get paths and to compromise root if Tomcat is run as root. Are these true?
- Are reports generated by JReport dynamic reports where users can interactively work with them on line?
- How do I licence remote users from different sites that connect to the main system?