cbcvebase.
CVE-2000-0672
published 2000-07-20

CVE-2000-0672: The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly…

PriorityP427medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
9.85%
95.1th percentile
The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory.

Affected

2 ranges
VendorProductVersion rangeFixed in
apachetomcat
apachetomcat
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.