CVE-2008-0002
Last modified
CVE-2008-0002 is a vulnerability of currently unknown severity. Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.. EPSS estimates a 5.06% chance of exploitation in the next 30 days.
Description
Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | 6.0.5 |
| Apache | Tomcat | 6.0.6 |
| Apache | Tomcat | 6.0.7 |
| Apache | Tomcat | 6.0.8 |
| Apache | Tomcat | 6.0.9 |
| Apache | Tomcat | 6.0.10 |
| Apache | Tomcat | 6.0.11 |
| Apache | Tomcat | 6.0.12 |
| Apache | Tomcat | 6.0.13 |
| Apache | Tomcat | 6.0.14 |
| Apache | Tomcat | 6.0.15 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-0002?
How severe is CVE-2008-0002?
How do I fix CVE-2008-0002?
Are you affected by CVE-2008-0002?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
