First published: Thu Nov 22 2001(Updated: )
Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Tomcat | =4.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0917 has a medium severity level as it allows remote attackers to access sensitive information.
To fix CVE-2001-0917, upgrade to a later version of Apache Tomcat that addresses this vulnerability.
CVE-2001-0917 can expose physical path information of the server, which can assist attackers in further exploits.
CVE-2001-0917 specifically affects Jakarta Tomcat version 4.0.1.
A potential workaround for CVE-2001-0917 is to avoid using long URLs with .JSP extensions in your application.