PT-2000-1691 · Apache · Jakarta Tomcat+1
Published
2000-10-20
·
Updated
2022-04-30
·
CVE-2000-0759
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Jakarta Tomcat version 3.1
Description
The issue allows a remote attacker to obtain physical path information when requesting a non-existent URL, resulting in an error message that includes the physical path. This occurs because requesting a non-existent JSP page generates an error page that includes the full file system path of the current context.
Recommendations
For Jakarta Tomcat version 3.1, consider configuring the server to handle errors in a way that does not reveal sensitive path information, such as by creating a custom error page. As a temporary workaround, restrict access to non-existent URLs to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Tomcat
Jakarta Tomcat