Red Hat Security Advisory 2017-0935-01

Discussion in 'News Aggregator' started by Packet Storm, 13 Apr 2017.

  1. Packet Storm

    Packet Storm Guest

    Red Hat Security Advisory 2017-0935-01 - Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages technologies. Security Fix: It was discovered that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other then their own.

    Continue reading...
     

Share This Page

Loading...