CVE-2007-2449
Summary
| CVE | CVE-2007-2449 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-06-14 23:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the ';' character, as demonstrated by a URI containing a "snp/snoop.jsp;" sequence. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Tomcat | 4.0.0 | All | All | All |
| Application | Apache | Tomcat | 4.0.1 | All | All | All |
| Application | Apache | Tomcat | 4.0.2 | All | All | All |
| Application | Apache | Tomcat | 4.0.3 | All | All | All |
| Application | Apache | Tomcat | 4.0.4 | All | All | All |
| Application | Apache | Tomcat | 4.0.5 | All | All | All |
| Application | Apache | Tomcat | 5.0.0 | All | All | All |
| Application | Apache | Tomcat | 5.0.1 | All | All | All |
| Application | Apache | Tomcat | 5.0.10 | All | All | All |
| Application | Apache | Tomcat | 5.0.11 | All | All | All |
| Application | Apache | Tomcat | 5.0.12 | All | All | All |
| Application | Apache | Tomcat | 5.0.13 | All | All | All |
| Application | Apache | Tomcat | 5.0.14 | All | All | All |
| Application | Apache | Tomcat | 5.0.15 | All | All | All |
| Application | Apache | Tomcat | 5.0.16 | All | All | All |
| Application | Apache | Tomcat | 5.0.17 | All | All | All |
| Application | Apache | Tomcat | 5.0.18 | All | All | All |
| Application | Apache | Tomcat | 5.0.19 | All | All | All |
| Application | Apache | Tomcat | 5.0.2 | All | All | All |
| Application | Apache | Tomcat | 5.0.21 | All | All | All |
| Application | Apache | Tomcat | 5.0.22 | All | All | All |
| Application | Apache | Tomcat | 5.0.23 | All | All | All |
| Application | Apache | Tomcat | 5.0.24 | All | All | All |
| Application | Apache | Tomcat | 5.0.25 | All | All | All |
| Application | Apache | Tomcat | 5.0.26 | All | All | All |
| Application | Apache | Tomcat | 5.0.27 | All | All | All |
| Application | Apache | Tomcat | 5.0.28 | All | All | All |
| Application | Apache | Tomcat | 5.0.29 | All | All | All |
| Application | Apache | Tomcat | 5.0.3 | All | All | All |
| Application | Apache | Tomcat | 5.0.30 | All | All | All |
| Application | Apache | Tomcat | 5.0.4 | All | All | All |
| Application | Apache | Tomcat | 5.0.5 | All | All | All |
| Application | Apache | Tomcat | 5.0.6 | All | All | All |
| Application | Apache | Tomcat | 5.0.7 | All | All | All |
| Application | Apache | Tomcat | 5.0.8 | All | All | All |
| Application | Apache | Tomcat | 5.0.9 | All | All | All |
| Application | Apache | Tomcat | 5.5.0 | All | All | All |
| Application | Apache | Tomcat | 5.5.1 | All | All | All |
| Application | Apache | Tomcat | 5.5.10 | All | All | All |
| Application | Apache | Tomcat | 5.5.11 | All | All | All |
| Application | Apache | Tomcat | 5.5.12 | All | All | All |
| Application | Apache | Tomcat | 5.5.13 | All | All | All |
| Application | Apache | Tomcat | 5.5.14 | All | All | All |
| Application | Apache | Tomcat | 5.5.15 | All | All | All |
| Application | Apache | Tomcat | 5.5.16 | All | All | All |
| Application | Apache | Tomcat | 5.5.17 | All | All | All |
| Application | Apache | Tomcat | 5.5.18 | All | All | All |
| Application | Apache | Tomcat | 5.5.19 | All | All | All |
| Application | Apache | Tomcat | 5.5.2 | All | All | All |
| Application | Apache | Tomcat | 5.5.20 | All | All | All |
| Application | Apache | Tomcat | 5.5.21 | All | All | All |
| Application | Apache | Tomcat | 5.5.22 | All | All | All |
| Application | Apache | Tomcat | 5.5.3 | All | All | All |
| Application | Apache | Tomcat | 5.5.4 | All | All | All |
| Application | Apache | Tomcat | 5.5.5 | All | All | All |
| Application | Apache | Tomcat | 5.5.6 | All | All | All |
| Application | Apache | Tomcat | 5.5.7 | All | All | All |
| Application | Apache | Tomcat | 5.5.8 | All | All | All |
| Application | Apache | Tomcat | 5.5.9 | All | All | All |
| Application | Apache | Tomcat | 6.0.0 | All | All | All |
| Application | Apache | Tomcat | 6.0.1 | All | All | All |
| Application | Apache | Tomcat | 6.0.10 | All | All | All |
| Application | Apache | Tomcat | 6.0.11 | All | All | All |
| Application | Apache | Tomcat | 6.0.12 | All | All | All |
| Application | Apache | Tomcat | 6.0.13 | All | All | All |
| Application | Apache | Tomcat | 6.0.2 | All | All | All |
| Application | Apache | Tomcat | 6.0.3 | All | All | All |
| Application | Apache | Tomcat | 6.0.4 | All | All | All |
| Application | Apache | Tomcat | 6.0.5 | All | All | All |
| Application | Apache | Tomcat | 6.0.6 | All | All | All |
| Application | Apache | Tomcat | 6.0.7 | All | All | All |
| Application | Apache | Tomcat | 6.0.8 | All | All | All |
| Application | Apache | Tomcat | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| HP-UX update for Apache - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| HPSBUX02262 SSRT071447 rev. 1 - HP-UX running Apache, Remote Arbitrary Code Execution, Cross Site Scripting (XSS) - c01178795 - HP Business Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | |
| SUSE Update for Multiple Packages - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| About the security content of Security Update 2008-004 and Mac OS X 10.5.4 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Red Hat update for Red Hat Network Satellite Server - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| SecurityReason - Apache Tomcat XSS vulnerabilities in the JSP examples | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Apache Tomcat® - Apache Tomcat 4.x vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Apache Tomcat JSP Example Web Applications Cross Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [security-announce] SUSE Security Summary Report SUSE-SR:2008:007 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| SecurityTracker.com Archives - Tomcat Input Validation Holes in the JSP Examples, Manager, and Host Manager Permit Cross-Site Scripting Attacks | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:004 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| APPLE-SA-2008-06-30 Security Update 2008-004 and Mac OS X v10.5.4 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Friday, January 23, 2009 - Posts - CA Security Response Blog - CA Technologies | af854a3a-2127-422b-91ae-364da2661108 | community.ca.com | |
| Advisories | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Apache Tomcat - Apache Tomcat 5 vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | |
| CA Cohesion Application Configuration Manager Apache Tomcat Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| access.redhat.com | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | support.ca.com | |
| [SECURITY] Fedora 7 Update: tomcat5-5.5.25-1jpp.1.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Red Hat update for tomcat - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Apache Tomcat® - Apache Tomcat 6 vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| osvdb.org/36080 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Fedora update for tomcat5 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995375 Java (Maven) Security Update for org.apache.tomcat:tomcat (GHSA-hc39-rjwp-qffq)