Description
Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to delete work-directory files via directory traversal sequences in a WAR filename, as demonstrated by the ...war filename.
CVSS vector
AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9Confidentiality: None
Availability: None
Affected Packages1 packages
🔴Vulnerability Details
3OSVImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Apache Tomcat↗2022-05-02 ▶ GHSAImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Apache Tomcat↗2022-05-02 ▶ CVEListCVE-2009-2902: Directory traversal vulnerability in Apache Tomcat 5↗2010-01-28 ▶ 📋Vendor Advisories
2UbuntuTomcat vulnerabilities↗2010-02-11 ▶ Red Hattomcat: unexpected file deletion in work directory↗2010-01-24 ▶ 💬Community
2BugzillaCVE-2009-2901 CVE-2009-2902 CVE-2009-2693 CVE-2010-1157 tomcat: multiple vulnerabilities [fedora-all]↗2010-04-23 ▶ BugzillaCVE-2009-2902 tomcat: unexpected file deletion in work directory↗2010-01-28 ▶