CVE-2015-5345Path Traversal in Apache Tomcat

Severity
5.3MEDIUMNVD
EPSS
14.8%
top 5.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 25
Latest updateMay 14

Description

The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a directory via a URL that lacks a trailing / (slash) character.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages1 packages

NVDapache/tomcat88 versions+87

Also affects: Debian Linux 7.0, 8.0, Ubuntu Linux 12.04, 14.04, 15.10, 16.04

🔴Vulnerability Details

5
OSV
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat2022-05-14
GHSA
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat2022-05-14
OSV
tomcat6, tomcat7 vulnerabilities2016-07-05
CVEList
CVE-2015-5345: The Mapper component in Apache Tomcat 62016-02-25
OSV
CVE-2015-5345: The Mapper component in Apache Tomcat 62016-02-24

📋Vendor Advisories

4
Ubuntu
Tomcat vulnerabilities2016-07-05
Red Hat
tomcat: directory disclosure2016-02-22
Debian
CVE-2015-5345: tomcat9 - The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x ...2015
Apache
Apache tomcat: CVE-2015-5345

💬Community

4
Bugzilla
CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 CVE-2016-3092 tomcat: multiple security vulnerabilities [epel-6]2016-07-01
Bugzilla
CVE-2015-5174 CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 tomcat: multiple security vulnerabilities [epel-6]2016-02-23
Bugzilla
CVE-2015-5345 tomcat: directory disclosure2016-02-23
Bugzilla
CVE-2015-5174 CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 tomcat: multiple security vulnerabilities [fedora-all]2016-02-23
CVE-2015-5345 — Path Traversal in Apache Tomcat | cvebase