CVE Vulnerabilities

CVE-2002-1394

Published: Jan 17, 2003 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.

Affected Software

Name Vendor Start Version End Version
Tomcat Apache 4.0.0 (including) 4.0.0 (including)
Tomcat Apache 4.0.1 (including) 4.0.1 (including)
Tomcat Apache 4.0.2 (including) 4.0.2 (including)
Tomcat Apache 4.0.3 (including) 4.0.3 (including)
Tomcat Apache 4.0.4 (including) 4.0.4 (including)
Tomcat Apache 4.0.5 (including) 4.0.5 (including)
Tomcat Apache 4.1.0 (including) 4.1.0 (including)
Tomcat Apache 4.1.3-beta (including) 4.1.3-beta (including)
Tomcat Apache 4.1.9-beta (including) 4.1.9-beta (including)
Tomcat Apache 4.1.10 (including) 4.1.10 (including)
Red Hat Stronghold 4 RedHat *
Stronghold 4 for Red Hat Enterprise Linux RedHat *

References