CVE-2002-2007
Summary
| CVE | CVE-2002-2007 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ProCheckup Ltd | af854a3a-2127-422b-91ae-364da2661108 | www.procheckup.com | |
| ProCheckup Ltd | af854a3a-2127-422b-91ae-364da2661108 | www.procheckup.com | |
| CERT/CC Vulnerability Note VU#116963 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Apache Tomcat Source.JSP Malformed Request Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| ISS X-Force Database: tomcat-sample-reveal-path (9208): Apache Tomcat sample file requests could reveal directory listing and path to Web root directory | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | |
| Vulnerability in Apache Tomcat v3.23 & v3.24 | af854a3a-2127-422b-91ae-364da2661108 | cert.uni-stuttgart.de | Exploit |
| ProCheckup Ltd | af854a3a-2127-422b-91ae-364da2661108 | www.procheckup.com | |
| Apache Tomcat Example Files Web Root Path Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| Apache Tomcat RealPath.JSP Malformed Request Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| Vulnerability in Apache Tomcat v3.23 & v3.24 (part 2) | af854a3a-2127-422b-91ae-364da2661108 | cert.uni-stuttgart.de | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.