First published: Wed Jan 29 2003(Updated: )
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.tomcat:tomcat | <3.3.1a | 3.3.1a |
Apache Tomcat | =3.1 | |
Apache Tomcat | =3.2.1 | |
Apache Tomcat | =3.2.4 | |
Apache Tomcat | =3.0 | |
Apache Tomcat | =3.1.1 | |
Apache Tomcat | =3.2.3 | |
Apache Tomcat | =3.2 | |
Apache Tomcat | =3.3.1 | |
Apache Tomcat | =3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.