Vulnerability Name: CVE-2008-2370 (CCN-44156) Assigned: 2008-08-01 Published: 2008-08-01 Updated: 2023-02-13 Summary: Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter. CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): NoneAvailibility (A): None
CVSS v2 Severity: 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N )3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): NoneAvailibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N )3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): NoneAvailibility (A): None
Vulnerability Consequences: Obtain Information References: Source: CCN Type: BugTraq Mailing List, Fri Aug 01 2008 - 09:06:33 CDT[CVE-2008-2370] Apache Tomcat information disclosure vulnerability Source: MITRE Type: CNACVE-2008-2370 Source: CCN Type: HP Security Bulletin HPSBUX02401 SSRT090005 rev.1HP-UX Running Apache Web Server Suite, Remote Denial of Service (DoS), Cross-site Scripting (XSS), Execution of Arbitrary Code, Cross-Site Request Forgery (CSRF) Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: CCN Type: Security-announce Mailing List, Mon Feb 23 18:39:14 PST 2009VMSA-2009-0002 VirtualCenter Update 4 updates Tomcat to 5.5.27 Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: CCN Type: RHSA-2008-0648Important: tomcat security update Source: CCN Type: RHSA-2008-0862Important: tomcat security update Source: CCN Type: RHSA-2008-0864Important: tomcat security update Source: CCN Type: RHSA-2008-0877Important: jbossweb security update Source: CCN Type: RHSA-2008-1007Low: tomcat security update for Red Hat Network Satellite Server Source: CCN Type: RHSA-2010-0602Moderate: Red Hat Certificate System 7.3 security update Source: CCN Type: SA31379Apache Tomcat Multiple Vulnerabilities Source: CCN Type: SA31381Apache Tomcat 6 Multiple Vulnerabilities Source: CCN Type: SA32222Apple Mac OS X Security Update Fixes Multiple Vulnerabilities Source: CCN Type: SA32266Avaya AES / MX Apache Tomcat Multiple Vulnerabilities Source: CCN Type: SA34013VMware Multiple Products Tomcat Vulnerabilities Source: CCN Type: SA34039Sun Solaris Tomcat Directory Traversal and Cross-Site Scripting Source: CCN Type: SA35393Fujitsu Interstage Products Information Disclosure Vulnerabilities Source: CCN Type: SA36249Apache ODE Process Deployment Web Service Directory Traversal Source: CCN Type: SA37460VMware Products Update for Multiple Packages Source: CCN Type: SA40425Novell ZENworks Linux Management Tomcat Multiple Vulnerabilities Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: CCN Type: SECTRACK ID: 1020623Tomcat RequestDispatcher Bug Lets Remote Users Bypass Access Restrictions Source: CCN Type: Sun Alert ID: 251986Security Vulnerabilities in Tomcat 5.5 may Lead to Cross Site Scripting (XSS) or Directory Traversal Source: CCN Type: Apple Web siteAbout Security Update 2008-007 Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: CCN Type: ASA-2008-390tomcat security update (RHSA-2008-0864) Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: CCN Type: ASA-2008-401tomcat security update (RHSA-2008-0862) Source: CCN Type: ASA-2009-061HPSBUX02401 SSRT090005 rev.2 - HP-UX Running Apache Web Server SuiteRemote Denial of Service (DoS) Cross-site Scripting (XSS) Execution of Arbitrary Code Cross-Site Request Forgery (CSRF) Source: CCN Type: ASA-2009-077Security Vulnerabilities in Tomcat 5.5 may Lead to Cross Site Scripting (XSS) or Directory Traversal (Sun 251986) Source: CCN Type: Apache Tomcat Web siteTomcat 6 Downloads Source: CCN Type: Apache Tomcat Security Web siteApache Tomcat 4.x vulnerabilities, Will not be fixed in Apache Tomcat 4.1.x Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: CCN Type: Fujitsu Web siteInterstage Application Server: Information Disclosure Vulnerabilities(CVE-2008-2370/CVE-2008-5515) Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: CCN Type: Novell Document ID: 7006398Tomcat 5.0.28 in ZLM 7.3 subject to "Multiple Vendor Multiple HTTP Request Smuggling Vulnerabilities" Source: CCN Type: OSVDB ID: 56903Apache ODE (Orchestration Director Engine) Process Deployment Web Service Traversal Arbitrary File Manipulation Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: CCN Type: BID-30494Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability Source: secalert@redhat.com Type: Exploit, Patchsecalert@redhat.com Source: CCN Type: BID-31681RETIRED: Apple Mac OS X 2008-007 Multiple Security Vulnerabilities Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: CCN Type: BID-35263Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: XF Type: UNKNOWNtomcat-requestdispatcher-dir-traversal(44156) Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: CCN Type: IBM Security Bulletin 6858013 (Tivoli Application Dependency Discovery Manager)TADDM affected by multiple vulnerabilities due to Apache Tomcat libraries Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: secalert@redhat.com Type: UNKNOWNsecalert@redhat.com Source: SUSE Type: SUSE-SR:2008:018SUSE Security Summary Report Source: SUSE Type: SUSE-SR:2009:004SUSE Security Summary Report Vulnerable Configuration: Configuration RedHat 1 :cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:* Configuration RedHat 2 :cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:* Configuration RedHat 3 :cpe:/o:redhat:enterprise_linux:5::client_workstation:*:*:*:*:* Configuration RedHat 4 :cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:* Configuration CCN 1 :cpe:/a:apache:tomcat:4.1.10:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.0:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.24:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.34:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.12:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.15:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.28:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.31:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.36:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:6.0.0:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:6.0.1:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:6.0.10:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:6.0.11:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:6.0.12:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:6.0.13:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:6.0.14:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:6.0.15:*:*:*:*:*:*:* OR cpe:/a:redhat:certificate_system:7.3:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:6.0.16:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.32:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.37:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.18:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.19:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.20:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.21:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.22:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.23:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.26:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.27:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.29:*:*:*:*:*:*:* OR cpe:/a:apache:tomcat:4.1.30:*:*:*:*:*:*:* AND cpe:/o:hp:hp-ux:b.11.11:*:*:*:*:*:*:* OR cpe:/o:sun:solaris:9::x86:*:*:*:*:* OR cpe:/o:hp:hp-ux:b.11.23:*:*:*:*:*:*:* OR cpe:/o:sun:solaris:10::sparc:*:*:*:*:* OR cpe:/o:sun:solaris:10::x86:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:5::client_workstation:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2008.0:x86_64:*:*:*:*:*:* OR cpe:/o:hp:hp-ux:b.11.31:*:*:*:*:*:*:* OR cpe:/a:redhat:network_satellite:5.0:*:*:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:* OR cpe:/a:redhat:rhel_developer_suite:3:*:*:*:*:*:*:* OR cpe:/a:redhat:rhel_application_server:2:*:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2008.1:x86_64:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.1:*:*:*:*:*:*:* OR cpe:/o:vmware:esx:3.0.2:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2008.1:*:*:*:*:*:*:* OR cpe:/a:vmware:esx_server:3.5:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.3:*:*:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_89::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_89::sparc:*:*:*:*:* OR cpe:/o:sun:solaris:9::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_95::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_95::x86:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.4:*:*:*:*:*:*:* OR cpe:/a:vmware:virtualcenter:2.0.2:*:*:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_01::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_02::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_13::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_19::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_22::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_39::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_47::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_64::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_79b::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_88::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_01::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_02::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_13::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_19::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_22::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_39::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_47::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_64::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_79b::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_88::sparc:*:*:*:*:* OR cpe:/a:vmware:esx_server:3.0.3:*:*:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_03::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_04::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_05::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_06::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_07::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_08::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_09::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_10::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_11::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_12::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_14::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_15::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_16::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_18::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_20::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_21::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_24::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_25::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_26::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_27::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_28::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_29::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_31::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_32::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_33::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_34::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_35::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_37::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_41::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_43::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_44::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_45::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_48::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_50::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_53::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_54::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_56::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_58::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_59::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_60::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_62::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_65::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_68::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_69::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_72::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_75::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_76::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_78::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_81::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_82::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_84::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_85::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_87::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_86::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_17::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_23::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_30::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_36::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_38::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_42::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_46::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_49::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_51::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_52::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_55::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_57::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_61::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_63::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_66::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_67::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_70::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_71::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_73::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_74::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_77::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_79::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_83::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_03::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_04::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_05::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_06::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_07::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_15::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_08::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_14::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_11::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_17::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_12::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_09::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_16::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_10::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_21::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_20::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_27::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_26::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_25::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_24::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_23::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_18::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_28::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_33::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_34::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_35::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_36::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_32::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_37::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_31::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_30::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_29::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_40::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_41::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_42::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_43::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_44::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_38::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_45::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_46::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_48::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_55::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_54::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_50::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_57::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_49::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_56::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_52::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_51::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_53::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_67::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_66::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_59::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_65::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_58::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_61::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_63::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_60::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_62::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_71::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_68::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_72::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_77::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_70::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_74::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_73::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_76::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_69::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_75::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_78::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_84::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_83::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_79::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_86::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_85::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_87::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_80::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_82::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_81::sparc:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.5:*:*:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_100::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_100::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_80::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_91::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_91::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_90::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_90::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_40::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_92::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_92::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_93::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_94::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_99::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_98::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_97::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_96::sparc:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_94::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_93::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_99::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_97::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_98::x86:*:*:*:*:* OR cpe:/o:sun:opensolaris:build_snv_96::x86:*:*:*:*:* OR cpe:/a:vmware:server:2.0:*:*:*:*:*:*:* OR cpe:/a:fujitsu:interstage_apworks:6.0:*:*:*:*:*:*:* OR cpe:/a:fujitsu:interstage_studio:10.0.0:*:*:*:*:*:*:* OR cpe:/a:fujitsu:interstage_job_workload_server:8.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:tivoli_application_dependency_discovery_manager:7.3.0.0:*:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
apache tomcat 4.1.10
apache tomcat 4.1.0
apache tomcat 4.1.24
apache tomcat 4.1.34
apache tomcat 4.1.12
apache tomcat 4.1.15
apache tomcat 4.1.28
apache tomcat 4.1.31
apache tomcat 4.1.36
apache tomcat 6.0.0
apache tomcat 6.0.1
apache tomcat 6.0.10
apache tomcat 6.0.11
apache tomcat 6.0.12
apache tomcat 6.0.13
apache tomcat 6.0.14
apache tomcat 6.0.15
redhat certificate system 7.3
apache tomcat 6.0.16
apache tomcat 4.1.32
apache tomcat 4.1.37
apache tomcat 4.1.18
apache tomcat 4.1.19
apache tomcat 4.1.20
apache tomcat 4.1.21
apache tomcat 4.1.22
apache tomcat 4.1.23
apache tomcat 4.1.26
apache tomcat 4.1.27
apache tomcat 4.1.29
apache tomcat 4.1.30
hp hp-ux b.11.11
sun solaris 9
hp hp-ux b.11.23
sun solaris 10
sun solaris 10
redhat enterprise linux 5
redhat enterprise linux 5
mandrakesoft mandrake linux 2008.0 x86_64
hp hp-ux b.11.31
redhat network satellite 5.0
redhat enterprise linux 5
redhat rhel developer suite 3
redhat rhel application server 2
mandrakesoft mandrake linux 2008.0
mandrakesoft mandrake linux 2008.1 x86_64
apple mac os x server 10.5
apple mac os x server 10.5.1
vmware esx 3.0.2
apple mac os x server 10.5.2
mandrakesoft mandrake linux 2008.1
vmware esx server 3.5
apple mac os x server 10.5.3
sun opensolaris build_snv_89
sun opensolaris build_snv_89
sun solaris 9
sun opensolaris build_snv_95
sun opensolaris build_snv_95
apple mac os x server 10.5.4
vmware virtualcenter 2.0.2
sun opensolaris build_snv_01
sun opensolaris build_snv_02
sun opensolaris build_snv_13
sun opensolaris build_snv_19
sun opensolaris build_snv_22
sun opensolaris build_snv_39
sun opensolaris build_snv_47
sun opensolaris build_snv_64
sun opensolaris build_snv_79b
sun opensolaris build_snv_88
sun opensolaris build_snv_01
sun opensolaris build_snv_02
sun opensolaris build_snv_13
sun opensolaris build_snv_19
sun opensolaris build_snv_22
sun opensolaris build_snv_39
sun opensolaris build_snv_47
sun opensolaris build_snv_64
sun opensolaris build_snv_79b
sun opensolaris build_snv_88
vmware esx server 3.0.3
sun opensolaris build_snv_03
sun opensolaris build_snv_04
sun opensolaris build_snv_05
sun opensolaris build_snv_06
sun opensolaris build_snv_07
sun opensolaris build_snv_08
sun opensolaris build_snv_09
sun opensolaris build_snv_10
sun opensolaris build_snv_11
sun opensolaris build_snv_12
sun opensolaris build_snv_14
sun opensolaris build_snv_15
sun opensolaris build_snv_16
sun opensolaris build_snv_18
sun opensolaris build_snv_20
sun opensolaris build_snv_21
sun opensolaris build_snv_24
sun opensolaris build_snv_25
sun opensolaris build_snv_26
sun opensolaris build_snv_27
sun opensolaris build_snv_28
sun opensolaris build_snv_29
sun opensolaris build_snv_31
sun opensolaris build_snv_32
sun opensolaris build_snv_33
sun opensolaris build_snv_34
sun opensolaris build_snv_35
sun opensolaris build_snv_37
sun opensolaris build_snv_41
sun opensolaris build_snv_43
sun opensolaris build_snv_44
sun opensolaris build_snv_45
sun opensolaris build_snv_48
sun opensolaris build_snv_50
sun opensolaris build_snv_53
sun opensolaris build_snv_54
sun opensolaris build_snv_56
sun opensolaris build_snv_58
sun opensolaris build_snv_59
sun opensolaris build_snv_60
sun opensolaris build_snv_62
sun opensolaris build_snv_65
sun opensolaris build_snv_68
sun opensolaris build_snv_69
sun opensolaris build_snv_72
sun opensolaris build_snv_75
sun opensolaris build_snv_76
sun opensolaris build_snv_78
sun opensolaris build_snv_81
sun opensolaris build_snv_82
sun opensolaris build_snv_84
sun opensolaris build_snv_85
sun opensolaris build_snv_87
sun opensolaris build_snv_86
sun opensolaris build_snv_17
sun opensolaris build_snv_23
sun opensolaris build_snv_30
sun opensolaris build_snv_36
sun opensolaris build_snv_38
sun opensolaris build_snv_42
sun opensolaris build_snv_46
sun opensolaris build_snv_49
sun opensolaris build_snv_51
sun opensolaris build_snv_52
sun opensolaris build_snv_55
sun opensolaris build_snv_57
sun opensolaris build_snv_61
sun opensolaris build_snv_63
sun opensolaris build_snv_66
sun opensolaris build_snv_67
sun opensolaris build_snv_70
sun opensolaris build_snv_71
sun opensolaris build_snv_73
sun opensolaris build_snv_74
sun opensolaris build_snv_77
sun opensolaris build_snv_79
sun opensolaris build_snv_83
sun opensolaris build_snv_03
sun opensolaris build_snv_04
sun opensolaris build_snv_05
sun opensolaris build_snv_06
sun opensolaris build_snv_07
sun opensolaris build_snv_15
sun opensolaris build_snv_08
sun opensolaris build_snv_14
sun opensolaris build_snv_11
sun opensolaris build_snv_17
sun opensolaris build_snv_12
sun opensolaris build_snv_09
sun opensolaris build_snv_16
sun opensolaris build_snv_10
sun opensolaris build_snv_21
sun opensolaris build_snv_20
sun opensolaris build_snv_27
sun opensolaris build_snv_26
sun opensolaris build_snv_25
sun opensolaris build_snv_24
sun opensolaris build_snv_23
sun opensolaris build_snv_18
sun opensolaris build_snv_28
sun opensolaris build_snv_33
sun opensolaris build_snv_34
sun opensolaris build_snv_35
sun opensolaris build_snv_36
sun opensolaris build_snv_32
sun opensolaris build_snv_37
sun opensolaris build_snv_31
sun opensolaris build_snv_30
sun opensolaris build_snv_29
sun opensolaris build_snv_40
sun opensolaris build_snv_41
sun opensolaris build_snv_42
sun opensolaris build_snv_43
sun opensolaris build_snv_44
sun opensolaris build_snv_38
sun opensolaris build_snv_45
sun opensolaris build_snv_46
sun opensolaris build_snv_48
sun opensolaris build_snv_55
sun opensolaris build_snv_54
sun opensolaris build_snv_50
sun opensolaris build_snv_57
sun opensolaris build_snv_49
sun opensolaris build_snv_56
sun opensolaris build_snv_52
sun opensolaris build_snv_51
sun opensolaris build_snv_53
sun opensolaris build_snv_67
sun opensolaris build_snv_66
sun opensolaris build_snv_59
sun opensolaris build_snv_65
sun opensolaris build_snv_58
sun opensolaris build_snv_61
sun opensolaris build_snv_63
sun opensolaris build_snv_60
sun opensolaris build_snv_62
sun opensolaris build_snv_71
sun opensolaris build_snv_68
sun opensolaris build_snv_72
sun opensolaris build_snv_77
sun opensolaris build_snv_70
sun opensolaris build_snv_74
sun opensolaris build_snv_73
sun opensolaris build_snv_76
sun opensolaris build_snv_69
sun opensolaris build_snv_75
sun opensolaris build_snv_78
sun opensolaris build_snv_84
sun opensolaris build_snv_83
sun opensolaris build_snv_79
sun opensolaris build_snv_86
sun opensolaris build_snv_85
sun opensolaris build_snv_87
sun opensolaris build_snv_80
sun opensolaris build_snv_82
sun opensolaris build_snv_81
apple mac os x server 10.5.5
sun opensolaris build_snv_100
sun opensolaris build_snv_100
sun opensolaris build_snv_80
sun opensolaris build_snv_91
sun opensolaris build_snv_91
sun opensolaris build_snv_90
sun opensolaris build_snv_90
sun opensolaris build_snv_40
sun opensolaris build_snv_92
sun opensolaris build_snv_92
sun opensolaris build_snv_93
sun opensolaris build_snv_94
sun opensolaris build_snv_99
sun opensolaris build_snv_98
sun opensolaris build_snv_97
sun opensolaris build_snv_96
sun opensolaris build_snv_94
sun opensolaris build_snv_93
sun opensolaris build_snv_99
sun opensolaris build_snv_97
sun opensolaris build_snv_98
sun opensolaris build_snv_96
vmware server 2.0
fujitsu interstage apworks 6.0
fujitsu interstage studio 10.0.0
fujitsu interstage job workload server 8.1.1
ibm tivoli application dependency discovery manager 7.3.0.0