CVE-2002-2007
The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2)…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 41.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 41.40% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- apache/tomcat
- Source
- cve@mitre.org
References
- http://cert.uni-stuttgart.de/archive/bugtraq/2002/05/msg00272.htmlExploit
- http://cert.uni-stuttgart.de/archive/bugtraq/2002/05/msg00275.htmlExploit
- http://www.iss.net/security_center/static/9208.php
- http://www.kb.cert.org/vuls/id/116963US Government Resource
- http://www.procheckup.com/security_info/vuln_pr0205.html
- http://www.procheckup.com/security_info/vuln_pr0206.html
- http://www.procheckup.com/security_info/vuln_pr0207.html
- http://www.securityfocus.com/bid/4876Exploit
- http://www.securityfocus.com/bid/4877Exploit
- http://www.securityfocus.com/bid/4878Exploit
- http://cert.uni-stuttgart.de/archive/bugtraq/2002/05/msg00272.htmlExploit
- http://cert.uni-stuttgart.de/archive/bugtraq/2002/05/msg00275.htmlExploit
- http://www.iss.net/security_center/static/9208.php
- http://www.kb.cert.org/vuls/id/116963US Government Resource
- http://www.procheckup.com/security_info/vuln_pr0205.html
- http://www.procheckup.com/security_info/vuln_pr0206.html
- http://www.procheckup.com/security_info/vuln_pr0207.html
- http://www.securityfocus.com/bid/4876Exploit
- http://www.securityfocus.com/bid/4877Exploit
- http://www.securityfocus.com/bid/4878Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.