PT-2000-1691 · Apache · Jakarta Tomcat+1

Published

2000-10-20

·

Updated

2022-04-30

·

CVE-2000-0759

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jakarta Tomcat version 3.1
Description The issue allows a remote attacker to obtain physical path information when requesting a non-existent URL, resulting in an error message that includes the physical path. This occurs because requesting a non-existent JSP page generates an error page that includes the full file system path of the current context.
Recommendations For Jakarta Tomcat version 3.1, consider configuring the server to handle errors in a way that does not reveal sensitive path information, such as by creating a custom error page. As a temporary workaround, restrict access to non-existent URLs to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2000-0759
GHSA-QG4G-6JCQ-RW93

Affected Products

Apache Tomcat
Jakarta Tomcat