CVE-2009-2902: Path Traversal
Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to delete work-directory files via directory traversal sequences in a WAR filename, as demonstrated by the ...war filename.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2902?
CVE-2009-2902 is classified as a high severity vulnerability due to its potential for remote exploitation and its effect on the Apache Tomcat server.
How do I fix CVE-2009-2902?
To fix CVE-2009-2902, upgrade to Apache Tomcat version 5.5.29 or 6.0.24 or later.
What versions of Apache Tomcat are affected by CVE-2009-2902?
CVE-2009-2902 affects Apache Tomcat versions 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20.
What type of vulnerability is CVE-2009-2902?
CVE-2009-2902 is a directory traversal vulnerability that allows unauthorized remote access to files in the work directory.
Can CVE-2009-2902 be exploited remotely?
Yes, CVE-2009-2902 can be exploited remotely by attackers to delete files using specially crafted WAR filenames.