Hi all,
We recently have gone through a security audit that included a security scan. During the scan it was brought to our attention that the servicedesk server has two security vulnerabilities. Both of these vulnerabilities seem to be directly related to service desk.
Issue # 1 - Web Server Uses Plain-Text Form Based Authentication -
Issue # 2 - Apache Tomcat Multiple Content Length Headers Information Disclosure Vulnerability
THREAT:
Obviously issue #1 is code related and issue # 2 is a known vulnerability in version 5.0.28 of Apache.
So my question is first can issue #1 be looked at by development and for issue #2 the only fix available is to upgrade to a later version of apache. Any idea if this will ever happen?
Thanks.
-Nick
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2090
http://tomcat.apache.org/security-5.html
http://www.securityfocus.com/bid/13873
| Fixed in Apache Tomcat 5.5.23, 5.0.SVN |
|
|