Hello,
We had a recent security audit, and our ServiceDesk server is being flagged for an Apache vulnerability.
It is recommended that we inquire about disabling Apache directory traversal at the server.
We need to resolve the following, please advise:
Apache Tomcat Directory Traversal Vulnerability
Port: 80
Protocol: TCP
Description: Apache Tomcat is the servlet container used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. Apache HTTP Server running with the Tomcat servlet container is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data. This vulnerability occurs when Apache Server and Tomcat are configured to interoperate with common proxy modules. Specifically, this issue arises because Apache HTTP server recognizes only the '/'
Solution: The vendor has released versions 5.5.22 and 6.0.10 to address this issue.
Thanks for your time,
Joe