SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-5461

Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request…

LOW 3.5EPSS 39.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 39.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.

CVSS 2.0
3.5 LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
EPSS
39.68% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
apache/tomcat
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.