First published: Fri Feb 07 2003(Updated: )
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tomcat | =3.1 | |
Tomcat | =3.2.1 | |
Tomcat | =3.2.4 | |
Tomcat | =3.0 | |
Tomcat | =3.1.1 | |
Tomcat | =3.2.3 | |
Tomcat | =3.2 | |
Tomcat | =3.3.1 | |
Tomcat | =3.3 | |
maven/org.apache.tomcat:tomcat | <3.3.1a | 3.3.1a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0043 is considered a medium severity vulnerability due to the potential for remote file reading.
To fix CVE-2003-0043, upgrade Jakarta Tomcat to version 3.3.1a or later.
CVE-2003-0043 affects Jakarta Tomcat versions 3.0 to 3.3.
Yes, CVE-2003-0043 can allow remote attackers to read sensitive portions of files through the web.xml file.
CVE-2003-0043 is a remote vulnerability that can be exploited by remote attackers.