Tomcat information disclosure vulnerability
Published Feb 12, 2008
5.8
MEDIUMCVSS 2.0
EPSS 5.02%
Description
Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.
Affected products
No data.
- 6.0.5
- 6.0.6
- 6.0.7
- 6.0.8
- 6.0.9
- 6.0.10
- 6.0.11
- 6.0.12
- 6.0.13
- 6.0.14
- 6.0.15
No data.
JBEAP 4.2.0 for RHEL 4
glassfish-javamail-0:1.4.0-0jpp.ep1.8
Fixed · RHSA-2008:0151
JBEAP 4.2.0 for RHEL 4
hibernate3-1:3.2.4-1.SP1_CP02.0jpp.ep1.1.el4
Fixed · RHSA-2008:0151
JBEAP 4.2.0 for RHEL 4
hibernate3-annotations-0:3.2.1-1.patch02.1jpp.ep1.2.el4
Fixed · RHSA-2008:0151
JBEAP 4.2.0 for RHEL 4
hibernate3-entitymanager-0:3.2.1-1jpp.ep1.6.el4
Fixed · RHSA-2008:0151
JBEAP 4.2.0 for RHEL 4
hsqldb-1:1.8.0.8-2.patch01.1jpp.ep1.1
Fixed · RHSA-2008:0151
JBEAP 4.2.0 for RHEL 4
jacorb-0:2.3.0-1jpp.ep1.4
Fixed · RHSA-2008:0151
JBEAP 4.2.0 for RHEL 4
jboss-aop-0:1.5.5-1.CP01.0jpp.ep1.1.el4
Fixed · RHSA-2008:0151
JBEAP 4.2.0 for RHEL 4
jboss-cache-0:1.4.1-4.SP8_CP01.1jpp.ep1.1.el4
Fixed · RHSA-2008:0151
JBEAP 4.2.0 for RHEL 4
jboss-remoting-0:2.2.2-3.SP4.0jpp.ep1.1
Fixed · RHSA-2008:0151
JBEAP 4.2.0 for RHEL 4
jboss-seam-0:1.2.1-1.ep1.3.el4
Fixed · RHSA-2008:0151
JBEAP 4.2.0 for RHEL 4
jbossas-0:4.2.0-3.GA_CP02.ep1.3.el4
Fixed · RHSA-2008:0151
JBEAP 4.2.0 for RHEL 4
jbossweb-0:2.0.0-3.CP05.0jpp.ep1.1
Fixed · RHSA-2008:0151
JBEAP 4.2.0 for RHEL 4
jbossws-jboss42-0:1.2.1-0jpp.ep1.2.el4
Fixed · RHSA-2008:0151
JBEAP 4.2.0 for RHEL 4
jcommon-0:1.0.12-1jpp.ep1.2.el4
Fixed · RHSA-2008:0151
JBEAP 4.2.0 for RHEL 4
jfreechart-0:1.0.9-1jpp.ep1.2.el4
Fixed · RHSA-2008:0151
JBEAP 4.2.0 for RHEL 4
jgroups-1:2.4.1-1.SP4.0jpp.ep1.2
Fixed · RHSA-2008:0151
JBEAP 4.2.0 for RHEL 4
rh-eap-docs-0:4.2.0-3.GA_CP02.ep1.1.el4
Fixed · RHSA-2008:0151
JBEAP 4.2.0 for RHEL 5
hibernate3-0:3.2.4-1.SP1_CP02.0jpp.ep1.1.el5.1
Fixed · RHSA-2008:0213
JBEAP 4.2.0 for RHEL 5
hibernate3-annotations-0:3.2.1-1.patch02.1jpp.ep1.2.el5.1
Fixed · RHSA-2008:0213
JBEAP 4.2.0 for RHEL 5
jacorb-0:2.3.0-1jpp.ep1.5.el5
Fixed · RHSA-2008:0213
JBEAP 4.2.0 for RHEL 5
jboss-aop-0:1.5.5-1.CP01.0jpp.ep1.1.el5
Fixed · RHSA-2008:0213
JBEAP 4.2.0 for RHEL 5
jboss-cache-0:1.4.1-4.SP8_CP01.1jpp.ep1.1.el5
Fixed · RHSA-2008:0213
JBEAP 4.2.0 for RHEL 5
jboss-remoting-0:2.2.2-3.SP4.0jpp.ep1.1.el5
Fixed · RHSA-2008:0213
JBEAP 4.2.0 for RHEL 5
jboss-seam-0:1.2.1-1.ep1.3.el5
Fixed · RHSA-2008:0213
JBEAP 4.2.0 for RHEL 5
jbossas-0:4.2.0-4.GA_CP02.ep1.3.el5.3
Fixed · RHSA-2008:0213
JBEAP 4.2.0 for RHEL 5
jbossweb-0:2.0.0-3.CP05.0jpp.ep1.1.el5
Fixed · RHSA-2008:0213
JBEAP 4.2.0 for RHEL 5
jcommon-0:1.0.12-1jpp.ep1.2.el5
Fixed · RHSA-2008:0213
JBEAP 4.2.0 for RHEL 5
jfreechart-0:1.0.9-1jpp.ep1.2.el5.1
Fixed · RHSA-2008:0213
JBEAP 4.2.0 for RHEL 5
rh-eap-docs-0:4.2.0-3.GA_CP02.ep1.1.el5.1
Fixed · RHSA-2008:0213
Red Hat Web Application Stack for RHEL 4
concurrent-0:1.3.4-7jpp.ep1.6.el4
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
glassfish-jaf-0:1.1.0-0jpp.ep1.10.el4
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
glassfish-javamail-0:1.4.0-0jpp.ep1.8
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
glassfish-jsf-0:1.2_04-1.p02.0jpp.ep1.18
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
glassfish-jstl-0:1.2.0-0jpp.ep1.2
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
hibernate3-1:3.2.4-1.SP1_CP02.0jpp.ep1.1.el4
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
hibernate3-annotations-0:3.2.1-1.patch02.1jpp.ep1.2.el4
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
hibernate3-entitymanager-0:3.2.1-1jpp.ep1.6.el4
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
hsqldb-1:1.8.0.8-2.patch01.1jpp.ep1.1
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
jacorb-0:2.3.0-1jpp.ep1.4
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
jboss-aop-0:1.5.5-1.CP01.0jpp.ep1.1.el4
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
jboss-cache-0:1.4.1-4.SP8_CP01.1jpp.ep1.1.el4
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
jboss-common-0:1.2.1-0jpp.ep1.2
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
jboss-remoting-0:2.2.2-3.SP4.0jpp.ep1.1
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
jboss-seam-0:1.2.1-1.ep1.3.el4
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
jbossas-0:4.2.0-3.GA_CP02.ep1.3.el4
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
jbossweb-0:2.0.0-3.CP05.0jpp.ep1.1
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
jbossws-wsconsume-impl-0:2.0.0-0jpp.ep1.3
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
jbossxb-0:1.0.0-2.SP1.0jpp.ep1.2.el4
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
jcommon-0:1.0.12-1jpp.ep1.2.el4
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
jfreechart-0:1.0.9-1jpp.ep1.2.el4
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
jgroups-1:2.4.1-1.SP4.0jpp.ep1.2
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
rh-eap-docs-0:4.2.0-3.GA_CP02.ep1.1.el4
Fixed · RHSA-2008:0158
Red Hat Web Application Stack for RHEL 4
wsdl4j-0:1.6.2-1jpp.ep1.8
Fixed · RHSA-2008:0158
| Product | Package | State | Advisory |
|---|---|---|---|
| JBEAP 4.2.0 for RHEL 4 | glassfish-javamail-0:1.4.0-0jpp.ep1.8 | Fixed | RHSA-2008:0151 |
| JBEAP 4.2.0 for RHEL 4 | hibernate3-1:3.2.4-1.SP1_CP02.0jpp.ep1.1.el4 | Fixed | RHSA-2008:0151 |
| JBEAP 4.2.0 for RHEL 4 | hibernate3-annotations-0:3.2.1-1.patch02.1jpp.ep1.2.el4 | Fixed | RHSA-2008:0151 |
| JBEAP 4.2.0 for RHEL 4 | hibernate3-entitymanager-0:3.2.1-1jpp.ep1.6.el4 | Fixed | RHSA-2008:0151 |
| JBEAP 4.2.0 for RHEL 4 | hsqldb-1:1.8.0.8-2.patch01.1jpp.ep1.1 | Fixed | RHSA-2008:0151 |
| JBEAP 4.2.0 for RHEL 4 | jacorb-0:2.3.0-1jpp.ep1.4 | Fixed | RHSA-2008:0151 |
| JBEAP 4.2.0 for RHEL 4 | jboss-aop-0:1.5.5-1.CP01.0jpp.ep1.1.el4 | Fixed | RHSA-2008:0151 |
| JBEAP 4.2.0 for RHEL 4 | jboss-cache-0:1.4.1-4.SP8_CP01.1jpp.ep1.1.el4 | Fixed | RHSA-2008:0151 |
| JBEAP 4.2.0 for RHEL 4 | jboss-remoting-0:2.2.2-3.SP4.0jpp.ep1.1 | Fixed | RHSA-2008:0151 |
| JBEAP 4.2.0 for RHEL 4 | jboss-seam-0:1.2.1-1.ep1.3.el4 | Fixed | RHSA-2008:0151 |
| JBEAP 4.2.0 for RHEL 4 | jbossas-0:4.2.0-3.GA_CP02.ep1.3.el4 | Fixed | RHSA-2008:0151 |
| JBEAP 4.2.0 for RHEL 4 | jbossweb-0:2.0.0-3.CP05.0jpp.ep1.1 | Fixed | RHSA-2008:0151 |
| JBEAP 4.2.0 for RHEL 4 | jbossws-jboss42-0:1.2.1-0jpp.ep1.2.el4 | Fixed | RHSA-2008:0151 |
| JBEAP 4.2.0 for RHEL 4 | jcommon-0:1.0.12-1jpp.ep1.2.el4 | Fixed | RHSA-2008:0151 |
| JBEAP 4.2.0 for RHEL 4 | jfreechart-0:1.0.9-1jpp.ep1.2.el4 | Fixed | RHSA-2008:0151 |
| JBEAP 4.2.0 for RHEL 4 | jgroups-1:2.4.1-1.SP4.0jpp.ep1.2 | Fixed | RHSA-2008:0151 |
| JBEAP 4.2.0 for RHEL 4 | rh-eap-docs-0:4.2.0-3.GA_CP02.ep1.1.el4 | Fixed | RHSA-2008:0151 |
| JBEAP 4.2.0 for RHEL 5 | hibernate3-0:3.2.4-1.SP1_CP02.0jpp.ep1.1.el5.1 | Fixed | RHSA-2008:0213 |
| JBEAP 4.2.0 for RHEL 5 | hibernate3-annotations-0:3.2.1-1.patch02.1jpp.ep1.2.el5.1 | Fixed | RHSA-2008:0213 |
| JBEAP 4.2.0 for RHEL 5 | jacorb-0:2.3.0-1jpp.ep1.5.el5 | Fixed | RHSA-2008:0213 |
| JBEAP 4.2.0 for RHEL 5 | jboss-aop-0:1.5.5-1.CP01.0jpp.ep1.1.el5 | Fixed | RHSA-2008:0213 |
| JBEAP 4.2.0 for RHEL 5 | jboss-cache-0:1.4.1-4.SP8_CP01.1jpp.ep1.1.el5 | Fixed | RHSA-2008:0213 |
| JBEAP 4.2.0 for RHEL 5 | jboss-remoting-0:2.2.2-3.SP4.0jpp.ep1.1.el5 | Fixed | RHSA-2008:0213 |
| JBEAP 4.2.0 for RHEL 5 | jboss-seam-0:1.2.1-1.ep1.3.el5 | Fixed | RHSA-2008:0213 |
| JBEAP 4.2.0 for RHEL 5 | jbossas-0:4.2.0-4.GA_CP02.ep1.3.el5.3 | Fixed | RHSA-2008:0213 |
| JBEAP 4.2.0 for RHEL 5 | jbossweb-0:2.0.0-3.CP05.0jpp.ep1.1.el5 | Fixed | RHSA-2008:0213 |
| JBEAP 4.2.0 for RHEL 5 | jcommon-0:1.0.12-1jpp.ep1.2.el5 | Fixed | RHSA-2008:0213 |
| JBEAP 4.2.0 for RHEL 5 | jfreechart-0:1.0.9-1jpp.ep1.2.el5.1 | Fixed | RHSA-2008:0213 |
| JBEAP 4.2.0 for RHEL 5 | rh-eap-docs-0:4.2.0-3.GA_CP02.ep1.1.el5.1 | Fixed | RHSA-2008:0213 |
| Red Hat Web Application Stack for RHEL 4 | concurrent-0:1.3.4-7jpp.ep1.6.el4 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | glassfish-jaf-0:1.1.0-0jpp.ep1.10.el4 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | glassfish-javamail-0:1.4.0-0jpp.ep1.8 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | glassfish-jsf-0:1.2_04-1.p02.0jpp.ep1.18 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | glassfish-jstl-0:1.2.0-0jpp.ep1.2 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | hibernate3-1:3.2.4-1.SP1_CP02.0jpp.ep1.1.el4 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | hibernate3-annotations-0:3.2.1-1.patch02.1jpp.ep1.2.el4 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | hibernate3-entitymanager-0:3.2.1-1jpp.ep1.6.el4 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | hsqldb-1:1.8.0.8-2.patch01.1jpp.ep1.1 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | jacorb-0:2.3.0-1jpp.ep1.4 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | jboss-aop-0:1.5.5-1.CP01.0jpp.ep1.1.el4 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | jboss-cache-0:1.4.1-4.SP8_CP01.1jpp.ep1.1.el4 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | jboss-common-0:1.2.1-0jpp.ep1.2 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | jboss-remoting-0:2.2.2-3.SP4.0jpp.ep1.1 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | jboss-seam-0:1.2.1-1.ep1.3.el4 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | jbossas-0:4.2.0-3.GA_CP02.ep1.3.el4 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | jbossweb-0:2.0.0-3.CP05.0jpp.ep1.1 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | jbossws-wsconsume-impl-0:2.0.0-0jpp.ep1.3 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | jbossxb-0:1.0.0-2.SP1.0jpp.ep1.2.el4 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | jcommon-0:1.0.12-1jpp.ep1.2.el4 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | jfreechart-0:1.0.9-1jpp.ep1.2.el4 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | jgroups-1:2.4.1-1.SP4.0jpp.ep1.2 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | rh-eap-docs-0:4.2.0-3.GA_CP02.ep1.1.el4 | Fixed | RHSA-2008:0158 |
| Red Hat Web Application Stack for RHEL 4 | wsdl4j-0:1.6.2-1jpp.ep1.8 | Fixed | RHSA-2008:0158 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.02% (0.05016) | 91.99th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.02% (0.05016) | 91.11th | v5 (v2026.06.15) |
| Mar 30, 2025 | 4.10% (0.04097) | 87.52th | v4 (v2025.03.14) |
| Mar 29, 2025 | 6.64% (0.06644) | 84.96th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.10% (0.04097) | 87.83th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.18% (0.00175) | 55.90th | v3 (v2023.03.01) |
| Jul 16, 2024 | 0.32% (0.00320) | 70.87th | v3 (v2023.03.01) |
| Jun 8, 2024 | 0.36% (0.00360) | 72.21th | v3 (v2023.03.01) |
| May 3, 2024 | 0.26% (0.00264) | 65.93th | v3 (v2023.03.01) |
| Feb 18, 2024 | 0.26% (0.00259) | 64.79th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.24% (0.00239) | 60.14th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.34% (0.07344) | 92.59th | v2 (v2022.01.01) |
| Apr 1, 2022 | 7.34% (0.07344) | 91.87th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.34% (0.07344) | 80.64th | v2 (v2022.01.01) |
References (39)
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=139344343412337&w=2 vendor-advisoryx_refsource_HP
- http://secunia.com/advisories/28834 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28915 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29711 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/32222 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/37460 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/57126 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200804-10.xml vendor-advisoryx_refsource_GENTOO
- http://securityreason.com/securityalert/3638 third-party-advisoryx_refsource_SREASON
- http://support.apple.com/kb/HT3216 x_refsource_CONFIRM
- http://tomcat.apache.org/security-6.html x_refsource_CONFIRM
- http://www.securityfocus.com/archive/1/487812/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/507985/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/27703 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/31681 vdb-entryx_refsource_BID
- http://www.vmware.com/security/advisories/VMSA-2009-0016.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2008/0488 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/2780 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/3316 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2008-0002 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=432327 Issue Tracking
- https://github.com/advisories/GHSA-5x5f-9r6q-q7mh Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2008-0002
- https://web.archive.org/web/20080214133036/http://secunia.com/advisories/28915
- https://web.archive.org/web/20080715062302/http://secunia.com/advisories/29711
- https://web.archive.org/web/20080724052339/http://secunia.com/advisories/28834
- https://web.archive.org/web/20081012021650/http://www.securityfocus.com/bid/27703
- https://web.archive.org/web/20081013050642/http://secunia.com/advisories/32222
- https://web.archive.org/web/20081120062646/http://securityreason.com/securityalert/3638
- https://web.archive.org/web/20081121133027/http://www.securityfocus.com/archive/1/487812/100/0/threaded
- https://web.archive.org/web/20091125140215/http://secunia.com/advisories/37460
- https://web.archive.org/web/20120825080137/http://www.securityfocus.com/bid/31681
- https://web.archive.org/web/20140723000733/http://secunia.com/advisories/57126
- https://web.archive.org/web/20150621204350/http://www.securityfocus.com/archive/1/507985/100/0/threaded
- https://www.cve.org/CVERecord?id=CVE-2008-0002
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00315.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00460.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.