CVE-2008-2938
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 99.7%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 99.71% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- apache/tomcat
- Source
- secalert@redhat.com
References
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=123376588623823&w=2Third Party Advisory
- http://secunia.com/advisories/31639Broken Link
- http://secunia.com/advisories/31865Broken Link
- http://secunia.com/advisories/31891Broken Link
- http://secunia.com/advisories/31982Broken Link
- http://secunia.com/advisories/32120Broken Link
- http://secunia.com/advisories/32222Broken Link
- http://secunia.com/advisories/32266Broken Link
- http://secunia.com/advisories/33797Broken Link
- http://secunia.com/advisories/37297Broken Link
- http://securityreason.com/securityalert/4148Third Party Advisory
- http://support.apple.com/kb/HT3216Third Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2008-401.htmThird Party Advisory
- http://tomcat.apache.org/security-4.htmlVendor Advisory
- http://tomcat.apache.org/security-5.htmlVendor Advisory
- http://tomcat.apache.org/security-6.htmlVendor Advisory
- http://www.kb.cert.org/vuls/id/343355Third Party Advisory, US Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:188Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0648.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0862.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0864.htmlThird Party Advisory
- http://www.securenetwork.it/ricerca/advisory/download/SN-2009-02.txtThird Party Advisory
- http://www.securityfocus.com/archive/1/495318/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/507729/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/30633Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/31681Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020665Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.