Lucene search

K
osvGoogleOSV:GHSA-8G4F-FH7F-4FWH
HistoryApr 30, 2022 - 6:22 p.m.

Apache Tomcat Default Installation Reveals Sensitive Information

2022-04-3018:22:18
Google
osv.dev
5

6.5 Medium

AI Score

Confidence

Low

0.017 Low

EPSS

Percentile

88.0%

The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.

6.5 Medium

AI Score

Confidence

Low

0.017 Low

EPSS

Percentile

88.0%