First published: Thu Aug 02 2001(Updated: )
Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.tomcat:tomcat-servlet-api | <3.2.2 | 3.2.2 |
Apache Tomcat | <=3.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0590 is considered a critical vulnerability due to its potential for unauthorized access to sensitive source code.
To fix CVE-2001-0590, upgrade your Apache Tomcat installation to version 3.2.2 or later.
CVE-2001-0590 affects Apache Tomcat versions prior to 3.2.2.
CVE-2001-0590 exploits a vulnerability in Apache Tomcat that allows remote attackers to read the source code of arbitrary JSP files.
There are no effective workarounds for CVE-2001-0590; the best approach is to upgrade Apache Tomcat.