tomcat RequestDispatcher information disclosure vulnerability
Published Aug 4, 2008
5.0
MEDIUMCVSS 2.0
EPSS 52.72%
Description
Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.
Affected products
No data.
- 4.1.0
- 4.1.1
- 4.1.2
- 4.1.3
- 4.1.4
- 4.1.5
- 4.1.6
- 4.1.7
- 4.1.8
- 4.1.9
- 4.1.10
- 4.1.11
- 4.1.12
- 4.1.13
- 4.1.14
- 4.1.15
- 4.1.16
- 4.1.17
- 4.1.18
- 4.1.19
- 4.1.20
- 4.1.21
- 4.1.22
- 4.1.23
- 4.1.24
- 4.1.25
- 4.1.26
- 4.1.27
- 4.1.28
- 4.1.29
- 4.1.30
- 4.1.31
- 4.1.32
- 4.1.33
- 4.1.34
- 4.1.35
- 4.1.36
- 4.1.37
- 5.5.0
- 5.5.1
- 5.5.2
- 5.5.3
- 5.5.4
- 5.5.5
- 5.5.6
- 5.5.7
- 5.5.8
- 5.5.9
- 5.5.10
- 5.5.11
- 5.5.12
- 5.5.13
- 5.5.14
- 5.5.15
- 5.5.16
- 5.5.17
- 5.5.18
- 5.5.19
- 5.5.20
- 5.5.21
- 5.5.22
- 5.5.23
- 5.5.24
- 5.5.25
- 5.5.26
- 6.0.0
- 6.0.1
- 6.0.2
- 6.0.3
- 6.0.4
- 6.0.5
- 6.0.6
- 6.0.7
- 6.0.8
- 6.0.9
- 6.0.10
- 6.0.11
- 6.0.12
- 6.0.13
- 6.0.14
- 6.0.15
- 6.0.16
No data.
JBEAP 4.2.0 for RHEL 4
jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el4
Fixed · RHSA-2008:0877
JBEAP 4.2.0 for RHEL 5
jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el5
Fixed · RHSA-2008:0877
RHAPS Version 2 for RHEL 4
tomcat5-0:5.5.23-0jpp_4rh.9
Fixed · RHSA-2008:0862
Red Hat Certificate System 7.3
ant-0:1.6.5-1jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
avalon-logkit-0:1.2-2jpp_4rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
axis-0:1.2.1-1jpp_3rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
classpathx-jaf-0:1.0-2jpp_6rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
classpathx-mail-0:1.1.1-2jpp_8rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
geronimo-specs-0:1.0-0.M4.1jpp_10rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
jakarta-commons-modeler-0:2.0-3jpp_2rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
log4j-0:1.2.12-1jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
mx4j-1:3.0.1-1jpp_4rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
pcsc-lite-0:1.3.3-3.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-ca-0:7.3.0-20.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-java-tools-0:7.3.0-10.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-kra-0:7.3.0-14.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-manage-0:7.3.0-19.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-native-tools-0:7.3.0-6.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-ocsp-0:7.3.0-13.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-tks-0:7.3.0-13.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
tomcat5-0:5.5.23-0jpp_4rh.16
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
xerces-j2-0:2.7.1-1jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
xml-commons-0:1.3.02-2jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Developer Suite V.3
tomcat5-0:5.5.23-0jpp_12rh
Fixed · RHSA-2008:0864
Red Hat Enterprise Linux 5
tomcat5-0:5.5.23-0jpp.7.el5_2.1
Fixed · RHSA-2008:0648
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el4
Fixed · RHSA-2008:0877
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el5
Fixed · RHSA-2008:0877
Red Hat Network Satellite Server v 5.0
tomcat5-0:5.0.30-0jpp_12rh
Fixed · RHSA-2008:1007
Red Hat Network Satellite Server v 5.1
tomcat5-0:5.0.30-0jpp_12rh
Fixed · RHSA-2008:1007
| Product | Package | State | Advisory |
|---|---|---|---|
| JBEAP 4.2.0 for RHEL 4 | jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el4 | Fixed | RHSA-2008:0877 |
| JBEAP 4.2.0 for RHEL 5 | jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el5 | Fixed | RHSA-2008:0877 |
| RHAPS Version 2 for RHEL 4 | tomcat5-0:5.5.23-0jpp_4rh.9 | Fixed | RHSA-2008:0862 |
| Red Hat Certificate System 7.3 | ant-0:1.6.5-1jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | avalon-logkit-0:1.2-2jpp_4rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | axis-0:1.2.1-1jpp_3rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | classpathx-jaf-0:1.0-2jpp_6rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | classpathx-mail-0:1.1.1-2jpp_8rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | geronimo-specs-0:1.0-0.M4.1jpp_10rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | jakarta-commons-modeler-0:2.0-3jpp_2rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | log4j-0:1.2.12-1jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | mx4j-1:3.0.1-1jpp_4rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | pcsc-lite-0:1.3.3-3.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-ca-0:7.3.0-20.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-java-tools-0:7.3.0-10.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-kra-0:7.3.0-14.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-manage-0:7.3.0-19.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-native-tools-0:7.3.0-6.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-ocsp-0:7.3.0-13.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-tks-0:7.3.0-13.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | tomcat5-0:5.5.23-0jpp_4rh.16 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | xerces-j2-0:2.7.1-1jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | xml-commons-0:1.3.02-2jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Developer Suite V.3 | tomcat5-0:5.5.23-0jpp_12rh | Fixed | RHSA-2008:0864 |
| Red Hat Enterprise Linux 5 | tomcat5-0:5.5.23-0jpp.7.el5_2.1 | Fixed | RHSA-2008:0648 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el4 | Fixed | RHSA-2008:0877 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el5 | Fixed | RHSA-2008:0877 |
| Red Hat Network Satellite Server v 5.0 | tomcat5-0:5.0.30-0jpp_12rh | Fixed | RHSA-2008:1007 |
| Red Hat Network Satellite Server v 5.1 | tomcat5-0:5.0.30-0jpp_12rh | Fixed | RHSA-2008:1007 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (21 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 52.72% (0.52716) | 98.94th | v5 (v2026.06.15) |
| Jun 15, 2026 | 52.72% (0.52716) | 98.83th | v5 (v2026.06.15) |
| May 24, 2026 | 87.96% (0.87959) | 99.49th | v4 (v2025.03.14) |
| Mar 30, 2025 | 88.99% (0.88991) | 99.50th | v4 (v2025.03.14) |
| Mar 29, 2025 | 86.89% (0.86891) | 99.30th | v4 (v2025.03.14) |
| Mar 17, 2025 | 88.99% (0.88991) | 99.51th | v4 (v2025.03.14) |
| Jan 6, 2025 | 14.71% (0.14713) | 95.77th | v3 (v2023.03.01) |
| Dec 17, 2024 | 13.54% (0.13538) | 95.58th | v3 (v2023.03.01) |
| Dec 12, 2024 | 10.40% (0.10397) | 95.25th | v3 (v2023.03.01) |
| Aug 10, 2024 | 10.07% (0.10073) | 95.01th | v3 (v2023.03.01) |
| Jul 5, 2024 | 1.86% (0.01865) | 88.50th | v3 (v2023.03.01) |
| May 31, 2024 | 1.53% (0.01530) | 87.07th | v3 (v2023.03.01) |
| Apr 25, 2024 | 1.82% (0.01819) | 88.03th | v3 (v2023.03.01) |
| Feb 13, 2024 | 1.37% (0.01372) | 85.87th | v3 (v2023.03.01) |
| Apr 24, 2023 | 1.14% (0.01140) | 82.64th | v3 (v2023.03.01) |
| Mar 14, 2023 | 1.16% (0.01163) | 82.72th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.58% (0.00581) | 74.74th | v3 (v2023.03.01) |
| Mar 6, 2023 | 73.46% (0.73462) | 99.29th | v2 (v2022.01.01) |
| Feb 13, 2023 | 73.46% (0.73462) | 99.28th | v2 (v2022.01.01) |
| Feb 3, 2023 | 69.96% (0.69964) | 99.14th | v2 (v2022.01.01) |
| Feb 4, 2022 | 73.46% (0.73462) | 99.13th | v2 (v2022.01.01) |
References (94)
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=123376588623823&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=139344343412337&w=2 vendor-advisoryx_refsource_HP
- http://secunia.com/advisories/31379 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31381 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31639 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31865 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31891 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31982 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/32120 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/32222 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/32266 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/33797 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/33999 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34013 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35393 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/36249 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/37460 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/57126 third-party-advisoryx_refsource_SECUNIA
- http://securityreason.com/securityalert/4099 third-party-advisoryx_refsource_SREASON
- http://support.apple.com/kb/HT3216 x_refsource_CONFIRM
- http://support.avaya.com/elmodocs2/security/ASA-2008-401.htm x_refsource_CONFIRM
- http://tomcat.apache.org/security-4.html x_refsource_CONFIRM
- http://tomcat.apache.org/security-5.html x_refsource_CONFIRM
- http://tomcat.apache.org/security-6.html x_refsource_CONFIRM
- http://www.fujitsu.com/global/support/software/security/products-f/interstage-200902e.html x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:188 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/support/errata/RHSA-2008-0648.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0862.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0864.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/495022/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/507985/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/30494 vdb-entryx_refsource_BIDExploitPatch
- http://www.securityfocus.com/bid/31681 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1020623 vdb-entryx_refsource_SECTRACK
- http://www.vmware.com/security/advisories/VMSA-2009-0002.html x_refsource_CONFIRM
- http://www.vmware.com/security/advisories/VMSA-2009-0016.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2008/2305 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/2780 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/2823 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/0320 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/0503 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/1535 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/2215 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/3316 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2008-2370 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=457934 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44156 vdb-entryx_refsource_XF
- https://github.com/advisories/GHSA-m8h8-6rvg-f4mg Advisory
- https://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3@%3Cdev.tomcat.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2008-2370
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10577 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5876 vdb-entrysignaturex_refsource_OVAL
- https://web.archive.org/web/20080827150120/http://securityreason.com/securityalert/4099
- https://web.archive.org/web/20090201124618/http://secunia.com/advisories/31381
- https://web.archive.org/web/20090201124623/http://secunia.com/advisories/31639
- https://web.archive.org/web/20090201124633/http://secunia.com/advisories/31891
- https://web.archive.org/web/20090201124638/http://secunia.com/advisories/32120
- https://web.archive.org/web/20090201124957/http://secunia.com/advisories/31982
- https://web.archive.org/web/20090201125002/http://secunia.com/advisories/32266
- https://web.archive.org/web/20090201141000/http://secunia.com/advisories/32222
- https://web.archive.org/web/20090207111236/http://secunia.com/advisories/33797
- https://web.archive.org/web/20090225175903/http://secunia.com/advisories/33999
- https://web.archive.org/web/20090228074535/http://secunia.com/advisories/31379
- https://web.archive.org/web/20090228074540/http://secunia.com/advisories/34013
- https://web.archive.org/web/20090308065055/http://secunia.com/advisories/31865
- https://web.archive.org/web/20090811003155/http://secunia.com/advisories/35393
- https://web.archive.org/web/20090828023853/http://secunia.com/advisories/36249
- https://web.archive.org/web/20100706231759/http://secunia.com/advisories/37460
- https://web.archive.org/web/20110714083521/http://www.securitytracker.com/id?1020623
- https://web.archive.org/web/20110714174318/http://www.securityfocus.com/bid/30494
- https://web.archive.org/web/20120719164745/http://www.securityfocus.com/archive/1/495022/100/0/threaded
- https://web.archive.org/web/20120724210029/http://www.securityfocus.com/bid/31681
- https://web.archive.org/web/20140723000733/http://secunia.com/advisories/57126
- https://web.archive.org/web/20150621204350/http://www.securityfocus.com/archive/1/507985/100/0/threaded
- https://www.cve.org/CVERecord?id=CVE-2008-2370
- https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00712.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00859.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00889.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.