← All CVEs

CVE-2007-5461

low · 3.5

Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.

3.5
CVSS
39.7%
EPSS (exploit prob.)
99th
EPSS percentile
2007-10-15
Published

AV:N/AC:M/Au:S/C:P/I:N/A:N

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
apachetomcat4.0.0
apachetomcat4.0.1
apachetomcat4.0.2
apachetomcat4.0.3
apachetomcat4.0.4
apachetomcat4.0.5
apachetomcat4.0.6
apachetomcat4.1.0
apachetomcat4.1.1
apachetomcat4.1.2
apachetomcat4.1.3
apachetomcat4.1.4
apachetomcat4.1.5
apachetomcat4.1.6
apachetomcat4.1.7
apachetomcat4.1.8
apachetomcat4.1.9
apachetomcat4.1.10
apachetomcat4.1.11
apachetomcat4.1.12
apachetomcat4.1.13
apachetomcat4.1.14
apachetomcat4.1.15
apachetomcat4.1.16
apachetomcat4.1.17
apachetomcat4.1.18
apachetomcat4.1.19
apachetomcat4.1.20
apachetomcat4.1.21
apachetomcat4.1.22
apachetomcat4.1.23
apachetomcat4.1.24
apachetomcat4.1.25
apachetomcat4.1.26
apachetomcat4.1.27
apachetomcat4.1.28
apachetomcat4.1.29
apachetomcat4.1.30
apachetomcat4.1.31
apachetomcat4.1.32

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-5461