5

CVE-2007-5366

The Tomcat 4.1-based Servlet Service in Fujitsu Interstage Application Server 7.0 through 9.0.0 and Interstage Apworks/Studio 7.0 through 9.0.0 allows remote attackers to obtain sensitive information (web root path) via unspecified vectors that trigger an error message, probably related to enabling the useCanonCaches Java Virtual Machine (JVM) option.

Data is provided by the National Vulnerability Database (NVD)
FujitsuInterstage Application Server Version7.0 Editionenterprise
FujitsuInterstage Application Server Version7.0 Editionplus
FujitsuInterstage Application Server Version7.0 Editionplus_developer
FujitsuInterstage Application Server Version7.0.1 Editionenterprise
FujitsuInterstage Application Server Version7.0.1 Editionplus
FujitsuInterstage Application Server Version8.0.0 Editionenterprise
FujitsuInterstage Application Server Version8.0.0 Editionstandard_j
FujitsuInterstage Application Server Version8.0.1 Editionenterprise
FujitsuInterstage Application Server Version8.0.1 Editionstandard_j
FujitsuInterstage Application Server Version8.0.2 Editionenterprise
FujitsuInterstage Application Server Version8.0.2 Editionstandard_j
FujitsuInterstage Application Server Version8.0.3 Editionenterprise
FujitsuInterstage Application Server Version8.0.3 Editionstandard_j
FujitsuInterstage Application Server Version9.0 Editionenterprise
FujitsuInterstage Application Server Version9.0 Editionstandard_j
FujitsuInterstage Application Server Version9.0a Editionenterprise
FujitsuInterstage Application Server Version9.0a Editionstandard_j
FujitsuInterstage Apworks Version7.0 Editionmodelers_j
FujitsuInterstage Apworks Version8.0 Editionenterprise
FujitsuInterstage Apworks Version8.0 Editionstandard_j
FujitsuInterstage Studio Version8.01 Editionenterprise
FujitsuInterstage Studio Version8.01 Editionstandard_j
FujitsuInterstage Studio Version9.0 Editionenterprise
FujitsuInterstage Studio Version9.0 Editionstandard_j
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.19% 0.38
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.