← All CVEs

CVE-2009-2902

medium · 4.3

Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to delete work-directory files via directory traversal sequences in a WAR filename, as demonstrated by the ...war filename.

4.3
CVSS
10.8%
EPSS (exploit prob.)
96th
EPSS percentile
2010-01-28
Published

AV:N/AC:M/Au:N/C:N/I:P/A:N

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
apachetomcat5.5.0
apachetomcat5.5.1
apachetomcat5.5.2
apachetomcat5.5.3
apachetomcat5.5.4
apachetomcat5.5.5
apachetomcat5.5.6
apachetomcat5.5.7
apachetomcat5.5.8
apachetomcat5.5.9
apachetomcat5.5.10
apachetomcat5.5.11
apachetomcat5.5.12
apachetomcat5.5.13
apachetomcat5.5.14
apachetomcat5.5.15
apachetomcat5.5.16
apachetomcat5.5.17
apachetomcat5.5.18
apachetomcat5.5.19
apachetomcat5.5.20
apachetomcat5.5.21
apachetomcat5.5.22
apachetomcat5.5.23
apachetomcat5.5.24
apachetomcat5.5.25
apachetomcat5.5.26
apachetomcat5.5.27
apachetomcat5.5.28
apachetomcat6.0
apachetomcat6.0.0
apachetomcat6.0.1
apachetomcat6.0.2
apachetomcat6.0.3
apachetomcat6.0.4
apachetomcat6.0.5
apachetomcat6.0.6
apachetomcat6.0.7
apachetomcat6.0.8
apachetomcat6.0.9

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-2902