Back

MEDIUM

tomcat directory traversal

Published Mar 16, 2007

Description

Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (73)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 16, 2007
Updated Aug 7, 2024
Reserved Jan 23, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Mar 14, 2007
GHSA-4PRH-GQW8-RGH5