CVE-2003-0042
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 46.0%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 46.03% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- apache/tomcat
- Source
- cve@mitre.org
References
- http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/Vendor Advisory
- http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txtVendor Advisory
- http://marc.info/?l=bugtraq&m=104394568616290&w=2
- http://secunia.com/advisories/7972
- http://secunia.com/advisories/7977
- http://www.ciac.org/ciac/bulletins/n-060.shtml
- http://www.debian.org/security/2003/dsa-246Patch, Vendor Advisory
- http://www.securityfocus.com/advisories/5111
- http://www.securityfocus.com/bid/6721
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11194
- http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/Vendor Advisory
- http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txtVendor Advisory
- http://marc.info/?l=bugtraq&m=104394568616290&w=2
- http://secunia.com/advisories/7972
- http://secunia.com/advisories/7977
- http://www.ciac.org/ciac/bulletins/n-060.shtml
- http://www.debian.org/security/2003/dsa-246Patch, Vendor Advisory
- http://www.securityfocus.com/advisories/5111
- http://www.securityfocus.com/bid/6721
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11194
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.