Apache Tomcat Default Installation Reveals Sensitive Information
Low severity
GitHub Reviewed
Published
Apr 30, 2022
to the GitHub Advisory Database
•
Updated Feb 12, 2024
Package
Affected versions
>= 4.0.0, < 4.1.0
>= 3.0, < 3.3a
Patched versions
4.1.0
3.3a
Description
Published by the National Vulnerability Database
Dec 31, 2002
Published to the GitHub Advisory Database
Apr 30, 2022
Last updated
Feb 12, 2024
Reviewed
Feb 12, 2024
The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.
References