CVE-2009-2696
Description
Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML." NOTE: this is due to a missing fix for CVE-2009-0781.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2009-2696 is a regression in Red Hat Enterprise Linux 5 where Tomcat failed to fix an XSS vulnerability in the calendar example application.
Vulnerability
A cross-site scripting (XSS) vulnerability exists in jsp/cal/cal2.jsp within the calendar application of the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5. This flaw is a missing fix for CVE-2009-0781; the RHSA-2009:1164 erratum for RHEL 5 did not include the patch as stated [2]. The vulnerability allows remote attackers to inject arbitrary web script or HTML via the time parameter due to invalid HTML [1]. Affected versions include all Tomcat installations on Red Hat Enterprise Linux 5 that shipped with the incomplete security update [2].
Exploitation
An attacker can exploit this flaw by sending a crafted HTTP request to the affected cal2.jsp page containing malicious script in the time parameter. No authentication is required, and the attack is within the same origin, requiring no special network position beyond access to the web server hosting the examples application.
Impact
Successful exploitation leads to reflected cross-site scripting (XSS) [1], allowing the attacker to execute arbitrary web script or HTML in the context of the victim's browser. This can result in session theft, credential theft, or other malicious actions performed on behalf of the authenticated user.
Mitigation
Red Hat addressed this regression in RHSA-2010:0580, released on 2010-08-02, which updated Tomcat to properly include the fix for CVE-2009-0781 [1][2]. Users should apply the update via Red Hat Network or by installing the patched packages. No known workarounds are documented; the vulnerable cal2.jsp example application can be removed or disabled if not needed.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- secunia.com/advisories/40813nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue Tracking
- www.redhat.com/support/errata/RHSA-2010-0580.htmlnvd
- www.vupen.com/english/advisories/2010/1986nvd
News mentions
0No linked articles in our index yet.