VulnerabilityModified
CVE-2002-1394
Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.
HIGH 7.5EPSS 5.85%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 5.85% probability · 93th percentile
- CISA KEV
- Not listed
- Affected
- apache/tomcat
- Source
- cve@mitre.org
References
- http://issues.apache.org/bugzilla/show_bug.cgi?id=13365
- http://marc.info/?l=bugtraq&m=103470282514938&w=2
- http://marc.info/?l=tomcat-dev&m=103417249325526&w=2
- http://www.debian.org/security/2003/dsa-225
- http://www.redhat.com/support/errata/RHSA-2003-075.html
- http://www.redhat.com/support/errata/RHSA-2003-082.html
- http://www.securityfocus.com/bid/6562
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10376
- https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E
- http://issues.apache.org/bugzilla/show_bug.cgi?id=13365
- http://marc.info/?l=bugtraq&m=103470282514938&w=2
- http://marc.info/?l=tomcat-dev&m=103417249325526&w=2
- http://www.debian.org/security/2003/dsa-225
- http://www.redhat.com/support/errata/RHSA-2003-075.html
- http://www.redhat.com/support/errata/RHSA-2003-082.html
- http://www.securityfocus.com/bid/6562
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10376
- https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.