CVE Vulnerabilities

CVE-2002-1394

Published: Jan 17, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.

Affected Software

NameVendorStart VersionEnd Version
TomcatApache4.0.0 (including)4.0.0 (including)
TomcatApache4.0.1 (including)4.0.1 (including)
TomcatApache4.0.2 (including)4.0.2 (including)
TomcatApache4.0.3 (including)4.0.3 (including)
TomcatApache4.0.4 (including)4.0.4 (including)
TomcatApache4.0.5 (including)4.0.5 (including)
TomcatApache4.1.0 (including)4.1.0 (including)
TomcatApache4.1.3-beta (including)4.1.3-beta (including)
TomcatApache4.1.9-beta (including)4.1.9-beta (including)
TomcatApache4.1.10 (including)4.1.10 (including)
Red Hat Stronghold 4RedHat*
Stronghold 4 for Red Hat Enterprise LinuxRedHat*

References