SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2003-0017

Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.

MEDIUM 5.0EPSS 6.44%

Does this matter?

Lower severity and a low EPSS score (6.44%). Track it; it rarely justifies an emergency change on its own.

Description

Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
6.44% probability · 93th percentile
CISA KEV
Not listed
Affected
apache/http server
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.