Lucene search

K
cve[email protected]CVE-2008-2938
HistoryAug 13, 2008 - 12:41 a.m.

CVE-2008-2938

2008-08-1300:41:00
CWE-22
web.nvd.nist.gov
56
6
cve-2008-2938
directory traversal
apache tomcat
version 4.1.0
version 5.5.0
version 6.0.0
vulnerability
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

7.5 High

AI Score

Confidence

High

0.971 High

EPSS

Percentile

99.8%

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.

Affected configurations

NVD
Node
apachetomcatRange4.0.04.1.37
OR
apachetomcatRange5.0.05.5.26
OR
apachetomcatRange6.0.06.0.16

References

Social References

More

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

7.5 High

AI Score

Confidence

High

0.971 High

EPSS

Percentile

99.8%