S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2021-44138 Scanner

CVE-2021-44138 scanner - Directory traversal vulnerability in Caucho Resin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.5k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-44138
7.5
CVSS

There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Caucho Resin is a high-performance application server used for web applications and API services. It is deployed by organizations worldwide to host critical Java applications, offering features like load balancing, clustering, and a lightweight web server. Resin supports a wide range of web technologies, making it a versatile platform for developers. It's designed for high traffic websites requiring reliable, fast, and scalable web infrastructure. The affected versions of Resin are widely used, making this vulnerability a significant security concern.

The vulnerability is present in versions 4.0.52 to 4.0.56 of Caucho Resin, where the server fails to properly sanitize file paths included in HTTP requests. Specifically, an attacker can include a semicolon (;) followed by a path traversal sequence (/../) to navigate to restricted directories. This flaw enables unauthorized file access, allowing the attacker to view files like web.xml and resin-web.xml, which should not be accessible from the web.

Exploiting this vulnerability could lead to the exposure of sensitive information stored on the server, including configuration details, credentials, and proprietary data. This information leakage can facilitate further attacks, such as server compromise, data manipulation, or elevation of privileges. In a worst-case scenario, it could lead to a full system compromise.

By leveraging the security scanning capabilities of the S4E platform, users can identify and address vulnerabilities like the Directory Traversal flaw in Caucho Resin. Our platform offers detailed vulnerability assessments, actionable remediation guidance, and continuous monitoring to protect your digital assets from emerging threats. Joining S4E not only enhances your security posture but also provides peace of mind through comprehensive cyber threat management.

 

References

Solution Advice
  1. Immediately upgrade Caucho Resin to the latest version, beyond 4.0.56, where the vulnerability has been addressed.
  2. Regularly update all software to mitigate vulnerabilities and reduce the attack surface.
  3. Implement a robust input validation mechanism to reject suspicious or malformed inputs.
  4. Use a security gateway or web application firewall (WAF) to filter out malicious traffic and requests.
  5. Conduct periodic security audits and vulnerability assessments to identify and remediate potential weaknesses in the application infrastructure.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-44138 scanner - Directory traversal vulnerability in Caucho Resin | S4E