Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12061
HistoryJan 15, 2019 - 9:11 a.m.

Directory Information Disclosure

2019-01-1509:11:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

0.004 Low

EPSS

Percentile

73.9%

Tomcat is vulnerable to directory information disclosure. When accessing a directory protected by a security constraint with a URL that did not need in a slash, Tomcat would redirect to the URL with the trailing slash, confirming the presence of the file, even if no access is permitted.