AFAIK there are no issues with the default install. But the default install does include the examples app - which allows any user to view your environment and probably set session variables which could easily allow a denial of service attack based on memory consumption.

But then again, if one leaves the example webapp available on a production box, someone is not doing their job since only absolutely needed webapps should be installed and available on a production server. (Why allocate memory for a webapp which shouldn't be used?)

-Tim

Jens Skripczynski wrote:
Ronnie Tartar:

Is there a mailing list for security warnings for tomcat?

Are there any security issues in a default tomcat install ?



Ciao


Jens Skripczynski


---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Reply via email to