掲載番号:NV09-012
脆弱性情報識別番号:CVE-2008-2370
Apache TomcatのRequestDispatcherに関するディレクトリトラバーサルの脆弱性
概要
Apache TomcatのRequestDispatcherには、URIからのクエリ文字列を削除する前にパスの正常化が動作するため、ディレクトリトラバーサルの脆弱性が存在します。
対象製品
WebOTX Application Server
- 対処方法
対象となる製品のバージョン:
- WebOTX Web Edition V6.x
- WebOTX Standard-J Edition V6.x
- WebOTX Standard Edition V6.x
- WebOTX Enterprise Edition V6.x
- WebOTX Application Server Web Edition V7.x〜V8.1
- WebOTX Application Server Standard-J Edition V7.x〜V8.1
- WebOTX Application Server Standard Edition V7.x〜V8.1
- WebOTX Application Server Enterprise Edition V7.x〜V8.1
- WebOTX UDDI Registry V1.1〜V7.1
- WebOTX 開発環境 V6.x
- WebOTX Developer V7.x〜V8.1
- WebOTX Enterprise Service Bus V6.4〜V7.x
- WebOTX SIP Application Server Standard Edition V7.x〜V8.1
別途パッチを用意しております。詳細につきましては弊社営業にお問合せください。
参考情報
更新情報