CVE-2015-5174Path Traversal in Apache Tomcat

CWE-22Path Traversal13 documents8 sources
Severity
4.3MEDIUMNVD
EPSS
3.7%
top 12.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 25
Latest updateMay 14

Description

Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application in a getResource, getResourceAsStream, or getResourcePaths call, as demonstrated by the $CATALINA_BASE/webapps directory.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages1 packages

NVDapache/tomcat82 versions+81

Also affects: Debian Linux 7.0, 8.0, Ubuntu Linux 12.04, 14.04, 15.10, 16.04

🔴Vulnerability Details

5
GHSA
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat2022-05-14
OSV
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat2022-05-14
OSV
tomcat6, tomcat7 vulnerabilities2016-07-05
CVEList
CVE-2015-5174: Directory traversal vulnerability in RequestUtil2016-02-25
OSV
CVE-2015-5174: Directory traversal vulnerability in RequestUtil2016-02-24

📋Vendor Advisories

3
Ubuntu
Tomcat vulnerabilities2016-07-05
Red Hat
tomcat: URL Normalization issue2016-02-22
Apache
Apache tomcat: CVE-2015-5174

💬Community

4
Bugzilla
CVE-2015-5174 CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 tomcat: multiple security vulnerabilities [epel-6]2016-02-23
Bugzilla
CVE-2015-5174 CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 tomcat: multiple security vulnerabilities [fedora-all]2016-02-23
Bugzilla
CVE-2015-5174 tomcat: URL Normalization issue [jbews-3.0.0]2015-09-23
Bugzilla
CVE-2015-5174 tomcat: URL Normalization issue2015-09-23
CVE-2015-5174 — Path Traversal in Apache Tomcat | cvebase