VulnerabilityModified
CVE-2003-0043
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.
MEDIUM 5.0EPSS 4.51%
Does this matter?
Lower severity and a low EPSS score (4.51%). Track it; it rarely justifies an emergency change on its own.
Description
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 4.51% probability · 91th percentile
- CISA KEV
- Not listed
- Affected
- apache/tomcat
- Source
- cve@mitre.org
References
- http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/Vendor Advisory
- http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txtVendor Advisory
- http://www.ciac.org/ciac/bulletins/n-060.shtml
- http://www.debian.org/security/2003/dsa-246
- http://www.securityfocus.com/advisories/5111
- http://www.securityfocus.com/bid/6722
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11195
- http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/Vendor Advisory
- http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txtVendor Advisory
- http://www.ciac.org/ciac/bulletins/n-060.shtml
- http://www.debian.org/security/2003/dsa-246
- http://www.securityfocus.com/advisories/5111
- http://www.securityfocus.com/bid/6722
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11195
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.