CVE-2008-0002: Infoleak
Published Feb 12, 2008
·Updated
Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.
Affected Software
12 affected componentsFixes available
maven/org.apache.tomcat:tomcat>=6.0.0<6.0.16
6.0.16
Apache Tomcat=6.0.5
Apache Tomcat=6.0.6
Apache Tomcat=6.0.7
Apache Tomcat=6.0.8
Apache Tomcat=6.0.9
Apache Tomcat=6.0.10
Apache Tomcat=6.0.11
Apache Tomcat=6.0.12
Apache Tomcat=6.0.13
Apache Tomcat=6.0.14
Apache Tomcat=6.0.15
Event History
Feb 12, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
May 1, 2022
Advisory Published
via GitHub·11:27 PM
Frequently Asked Questions
1
What is the severity of CVE-2008-0002?
CVE-2008-0002 is categorized as a medium severity vulnerability.
2
How do I fix CVE-2008-0002?
To fix CVE-2008-0002, upgrade Apache Tomcat to version 6.0.16 or later.
3
What versions of Apache Tomcat are affected by CVE-2008-0002?
CVE-2008-0002 affects Apache Tomcat versions 6.0.0 through 6.0.15.
4
What type of vulnerability is CVE-2008-0002?
CVE-2008-0002 is an information disclosure vulnerability.
5
Can CVE-2008-0002 be exploited remotely?
Yes, CVE-2008-0002 can potentially be exploited by remote attackers.