Apache Tomcat examples directory vulnerabilities

Description
  • Apache Tomcat default installation contains the "/examples" directory which has many example servlets and JSPs. Some of these examples are a security risk and should not be deployed on a production server. <br/> The Sessions Example servlet (installed at <span class="bb-dark">/examples/servlets/servlet/SessionExample</span>) allows session manipulation. Because the session is global this servlet poses a big security risk as an attacker can potentitally become an administrator by manipulating its session.
Remediation
  • Disable public access to the examples directory.
References