CVE Vulnerabilities

CVE-2003-0042

Published: Feb 07, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.

Affected Software

NameVendorStart VersionEnd Version
TomcatApache3.0 (including)3.0 (including)
TomcatApache3.1 (including)3.1 (including)
TomcatApache3.1.1 (including)3.1.1 (including)
TomcatApache3.2 (including)3.2 (including)
TomcatApache3.2.1 (including)3.2.1 (including)
TomcatApache3.2.3 (including)3.2.3 (including)
TomcatApache3.2.4 (including)3.2.4 (including)
TomcatApache3.3 (including)3.3 (including)
TomcatApache3.3.1 (including)3.3.1 (including)

References