CVE-2009-2693: Path Traversal
Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrated by a ../../bin/catalina.bat entry.
Other sources
Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrated by a ../../bin/catalina.bat entry.
— GitHub
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2693?
CVE-2009-2693 has a high severity rating due to its potential for remote exploitation through directory traversal.
How do I fix CVE-2009-2693?
To mitigate CVE-2009-2693, upgrade to Apache Tomcat version 5.5.29 or later for the 5.5 series or version 6.0.24 or later for the 6.0 series.
What versions of Apache Tomcat are affected by CVE-2009-2693?
CVE-2009-2693 affects Apache Tomcat versions 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20.
What is the impact of CVE-2009-2693 on affected systems?
The impact of CVE-2009-2693 allows remote attackers to create or overwrite arbitrary files on the server, leading to potential information disclosure or system compromise.
Is it safe to use Apache Tomcat versions 5.5.29 or 6.0.24 and later regarding CVE-2009-2693?
Yes, using Apache Tomcat versions 5.5.29 and 6.0.24 and later mitigates the vulnerabilities related to CVE-2009-2693.