CVE-2008-0002

Apache Tomcat Sensitive Information Disclosure in maven/org.apache.tomcat/tomcat

Identifiers

GHSA-5x5f-9r6q-q7mh, CVE-2008-0002

Package Slug

maven/org.apache.tomcat/tomcat

Vulnerability

Apache Tomcat Sensitive Information Disclosure

Description

Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.

Affected Versions

All versions starting from 6.0.0 before 6.0.16

Solution

Upgrade to version 6.0.16 or above.

Last Modified

2024-02-12

source