tomcat Unicode directory traversal vulnerability
Published Aug 13, 2008
4.3
MEDIUMCVSS 2.0
EPSS 99.71%
Description
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.
Affected products
No data.
No data.
JBEAP 4.2.0 for RHEL 4
jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el4
Fixed · RHSA-2008:0877
JBEAP 4.2.0 for RHEL 5
jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el5
Fixed · RHSA-2008:0877
RHAPS Version 2 for RHEL 4
tomcat5-0:5.5.23-0jpp_4rh.9
Fixed · RHSA-2008:0862
Red Hat Developer Suite V.3
tomcat5-0:5.5.23-0jpp_12rh
Fixed · RHSA-2008:0864
Red Hat Enterprise Linux 5
tomcat5-0:5.5.23-0jpp.7.el5_2.1
Fixed · RHSA-2008:0648
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el4
Fixed · RHSA-2008:0877
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el5
Fixed · RHSA-2008:0877
Red Hat Network Satellite Server v 5.0
tomcat5-0:5.0.30-0jpp_12rh
Fixed · RHSA-2008:1007
Red Hat Network Satellite Server v 5.1
tomcat5-0:5.0.30-0jpp_12rh
Fixed · RHSA-2008:1007
| Product | Package | State | Advisory |
|---|---|---|---|
| JBEAP 4.2.0 for RHEL 4 | jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el4 | Fixed | RHSA-2008:0877 |
| JBEAP 4.2.0 for RHEL 5 | jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el5 | Fixed | RHSA-2008:0877 |
| RHAPS Version 2 for RHEL 4 | tomcat5-0:5.5.23-0jpp_4rh.9 | Fixed | RHSA-2008:0862 |
| Red Hat Developer Suite V.3 | tomcat5-0:5.5.23-0jpp_12rh | Fixed | RHSA-2008:0864 |
| Red Hat Enterprise Linux 5 | tomcat5-0:5.5.23-0jpp.7.el5_2.1 | Fixed | RHSA-2008:0648 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el4 | Fixed | RHSA-2008:0877 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el5 | Fixed | RHSA-2008:0877 |
| Red Hat Network Satellite Server v 5.0 | tomcat5-0:5.0.30-0jpp_12rh | Fixed | RHSA-2008:1007 |
| Red Hat Network Satellite Server v 5.1 | tomcat5-0:5.0.30-0jpp_12rh | Fixed | RHSA-2008:1007 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 99.71% (0.99708) | 99.95th | v5 (v2026.06.15) |
| Jun 15, 2026 | 99.71% (0.99708) | 99.95th | v5 (v2026.06.15) |
| Mar 17, 2025 | 93.22% (0.93218) | 99.80th | v4 (v2025.03.14) |
| Dec 12, 2024 | 96.77% (0.96769) | 99.73th | v3 (v2023.03.01) |
| Aug 11, 2024 | 97.10% (0.97096) | 99.82th | v3 (v2023.03.01) |
| Aug 10, 2024 | 96.06% (0.96056) | 99.53th | v3 (v2023.03.01) |
| Feb 22, 2024 | 97.09% (0.97094) | 99.75th | v3 (v2023.03.01) |
| Jan 16, 2024 | 96.71% (0.96709) | 99.58th | v3 (v2023.03.01) |
| Dec 10, 2023 | 96.64% (0.96640) | 99.54th | v3 (v2023.03.01) |
| Nov 8, 2023 | 96.88% (0.96876) | 99.62th | v3 (v2023.03.01) |
| Nov 6, 2023 | 97.22% (0.97221) | 99.77th | v3 (v2023.03.01) |
| Oct 2, 2023 | 97.27% (0.97266) | 99.79th | v3 (v2023.03.01) |
| May 3, 2023 | 97.33% (0.97331) | 99.78th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.35% (0.97350) | 99.78th | v3 (v2023.03.01) |
| Mar 6, 2023 | 80.13% (0.80128) | 99.51th | v2 (v2022.01.01) |
| Feb 4, 2022 | 80.13% (0.80128) | 99.41th | v2 (v2022.01.01) |
References (73)
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html vendor-advisoryx_refsource_APPLEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://marc.info/?l=bugtraq&m=123376588623823&w=2 vendor-advisoryx_refsource_HPThird Party Advisory
- http://secunia.com/advisories/31639 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/31865 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/31891 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/31982 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/32120 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/32222 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/32266 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/33797 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/37297 third-party-advisoryx_refsource_SECUNIABroken Link
- http://securityreason.com/securityalert/4148 third-party-advisoryx_refsource_SREASONThird Party Advisory
- http://support.apple.com/kb/HT3216 x_refsource_CONFIRMThird Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2008-401.htm x_refsource_CONFIRMThird Party Advisory
- http://tomcat.apache.org/security-4.html x_refsource_CONFIRMVendor Advisory
- http://tomcat.apache.org/security-5.html x_refsource_CONFIRMVendor Advisory
- http://tomcat.apache.org/security-6.html x_refsource_CONFIRMVendor Advisory
- http://www.kb.cert.org/vuls/id/343355 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:188 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0648.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0862.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0864.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.securenetwork.it/ricerca/advisory/download/SN-2009-02.txt x_refsource_MISCThird Party Advisory
- http://www.securityfocus.com/archive/1/495318/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/507729/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/30633 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/31681 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1020665 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2008/2343 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2008/2780 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2008/2823 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2009/0320 vdb-entryx_refsource_VUPENThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2008-2938 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=456120 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44411 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://github.com/advisories/GHSA-m7xj-ccqc-p4g2 Advisory
- https://github.com/apache/tomcat/commit/c55ad56ed72ee1dbfe790bc5492d4df74e3e754f
- https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3@%3Cdev.tomcat.apache.org%3E
- https://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
- https://nvd.nist.gov/vuln/detail/CVE-2008-2938
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10587 vdb-entrysignaturex_refsource_OVALTool Signature
- https://web.archive.org/web/20080827130946/http://securityreason.com/securityalert/4148
- https://web.archive.org/web/20090201124623/http://secunia.com/advisories/31639
- https://web.archive.org/web/20090201124633/http://secunia.com/advisories/31891
- https://web.archive.org/web/20090201124638/http://secunia.com/advisories/32120
- https://web.archive.org/web/20090201124957/http://secunia.com/advisories/31982
- https://web.archive.org/web/20090201125002/http://secunia.com/advisories/32266
- https://web.archive.org/web/20090201141000/http://secunia.com/advisories/32222
- https://web.archive.org/web/20090207111236/http://secunia.com/advisories/33797
- https://web.archive.org/web/20090308065055/http://secunia.com/advisories/31865
- https://web.archive.org/web/20100516085845/http://secunia.com/advisories/37297
- https://web.archive.org/web/20110711210039/http://rhn.redhat.com/errata/RHSA-2008-0862.html
- https://web.archive.org/web/20110713233239/http://rhn.redhat.com/errata/RHSA-2008-0648.html
- https://web.archive.org/web/20110713234158/http://rhn.redhat.com/errata/RHSA-2008-0864.html
- https://web.archive.org/web/20140628064423/http://www.securityfocus.com/archive/1/495318/100/0/threaded
- https://web.archive.org/web/20140628064448/http://www.securityfocus.com/archive/1/507729/100/0/threaded
- https://web.archive.org/web/20140826163457/http://www.securityfocus.com/bid/30633
- https://web.archive.org/web/20140826171227/http://www.securitytracker.com/id?1020665
- https://web.archive.org/web/20140826232500/http://www.securityfocus.com/bid/31681
- https://web.archive.org/web/20140827130327/http://www.securenetwork.it/ricerca/advisory/download/SN-2009-02.txt
- https://web.archive.org/web/20200612070417/http://marc.info/?l=bugtraq&m=123376588623823&w=2
- https://www.cve.org/CVERecord?id=CVE-2008-2938
- https://www.exploit-db.com/exploits/6229 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00712.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00859.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00889.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
Change history (0)
No recorded changes yet.