| Vulnerability Name: | CVE-2001-0590 (CCN-6971) | ||||||||
| Assigned: | 2001-04-03 | ||||||||
| Published: | 2001-04-03 | ||||||||
| Updated: | 2017-10-10 | ||||||||
| Summary: | Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0). | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: BUGTRAQ Type: Exploit, Vendor Advisory 20010403 Re: Tomcat may reveal script source code by URL trickery Source: CCN Type: BugTraq Mailing List, Tue Apr 03 2001 - 15:47:23 CDT Re: Tomcat may reveal script source code by URL trickery Source: MITRE Type: CNA CVE-2001-0590 Source: CCN Type: Hewlett-Packard Company Security Bulletin HPSBTL0112-004 Sec. Vulnerability in Tomcat 3.2.1 Source: CCN Type: US-CERT VU#208131 Jakarta Tomcat serves JSP source code when supplied malformed HTTP request Source: OSVDB Type: UNKNOWN 5580 Source: CCN Type: OSVDB ID: 5580 Apache Tomcat Servlet Malformed URL JSP Source Disclosure Source: HP Type: UNKNOWN HPSBTL0112-004 Source: XF Type: UNKNOWN jakarta-tomcat-jsp-source(6971) Source: XF Type: UNKNOWN jakarta-tomcat-jsp-source(6971) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||