blob: 1a60e4762af3b19ec6053b0f51fceff495fba6ef [file]
<!DOCTYPE html SYSTEM "about:legacy-compat">
<html lang="en"><head><META http-equiv="Content-Type" content="text/html; charset=UTF-8"><meta name="viewport" content="width=device-width, initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" type="text/css"><title>Apache Tomcat&reg; - Apache Tomcat 3.x vulnerabilities</title><meta name="author" content="Apache Tomcat Project"><script src="https://www.apachecon.com/event-images/snippet.js"></script></head><body><div id="wrapper"><header id="header"><div class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div class="hamburger"></div></div><a href="http://tomcat.apache.org/"><img class="tomcat-logo pull-left noPrint" alt="Tomcat Home" src="res/images/tomcat.png"></a><h1 class="pull-left">Apache Tomcat<sup>&reg;</sup></h1><div class="asf-logos pull-right"><a href="https://www.apache.org/foundation/contributing.html" target="_blank" class="pull-left"><img src="https://www.apache.org/images/SupportApache-small.png" class="support-asf" alt="Support Apache"></a><a href="http://www.apache.org/" target="_blank" class="pull-left"><img src="res/images/asf_logo_wide.svg" class="asf-logo" alt="The Apache Software Foundation"></a></div></div></header><main id="middle"><div><div id="mainLeft"><div id="nav-wrapper"><form action="https://www.google.com/search" method="get"><div class="searchbox"><input value="tomcat.apache.org" name="sitesearch" type="hidden"><input aria-label="Search text" placeholder="Search&hellip;" required="required" name="q" id="query" type="search"><button>GO</button></div></form><div class="asfevents"><a class="acevent" data-format="square" data-width="150"></a></div><nav><div><h2>Apache Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a href="./whichversion.html">Which version?</a></li><li><a href="https://tomcat.apache.org/download-11.cgi">Tomcat 11</a></li><li><a href="https://tomcat.apache.org/download-10.cgi">Tomcat 10</a></li><li><a href="https://tomcat.apache.org/download-90.cgi">Tomcat 9</a></li><li><a href="https://tomcat.apache.org/download-migration.cgi">Tomcat Migration Tool for Jakarta EE</a></li><li><a href="https://tomcat.apache.org/download-connectors.cgi">Tomcat Connectors</a></li><li><a href="https://tomcat.apache.org/download-native.cgi">Tomcat Native</a></li><li><a href="https://tomcat.apache.org/download-taglibs.cgi">Taglibs</a></li><li><a href="https://archive.apache.org/dist/tomcat/">Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a href="./tomcat-11.0-doc/index.html">Tomcat 11.0</a></li><li><a href="./tomcat-10.1-doc/index.html">Tomcat 10.1</a></li><li><a href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a href="./upgrading.html">Upgrading</a></li><li><a href="./connectors-doc/index.html">Tomcat Connectors</a></li><li><a href="./native-doc/index.html">Tomcat Native 2</a></li><li><a href="./native-1.3-doc/index.html">Tomcat Native 1.3</a></li><li><a href="https://cwiki.apache.org/confluence/display/TOMCAT">Wiki</a></li><li><a href="./migration.html">Migration Guide</a></li><li><a href="./presentations.html">Presentations</a></li><li><a href="https://cwiki.apache.org/confluence/x/Bi8lBg">Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a href="./security.html">Security Reports</a></li><li><a href="./findhelp.html">Find help</a></li><li><a href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ">FAQ</a></li><li><a href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug Database</a></li></ul></div><div><h2>Get Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a href="./source.html">Source code</a></li><li><a href="./ci.html">Buildbot</a></li><li><a href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a href="https://www.youtube.com/c/ApacheTomcatOfficial">YouTube</a></li></ul></div><div><h2>Misc</h2><ul><li><a href="./whoweare.html">Who We Are</a></li><li><a href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat">Swag</a></li><li><a href="./heritage.html">Heritage</a></li><li><a href="http://www.apache.org">Apache Home</a></li><li><a href="./resources.html">Resources</a></li><li><a href="./contact.html">Contact</a></li><li><a href="./legal.html">Legal</a></li><li><a href="https://privacy.apache.org/policies/privacy-policy-public.html">Privacy</a></li><li><a href="https://www.apache.org/foundation/contributing.html">Support Apache</a></li><li><a href="https://www.apache.org/foundation/sponsorship.html">Sponsorship</a></li><li><a href="http://www.apache.org/foundation/thanks.html">Thanks</a></li><li><a href="http://www.apache.org/licenses/">License</a></li></ul></div></nav></div></div><div id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 id="Apache_Tomcat_3.x_vulnerabilities">Apache Tomcat 3.x vulnerabilities</h3><div class="text">
<p>This page lists all security vulnerabilities fixed in released versions
of Apache Tomcat<sup>&reg;</sup> 3.x. Each vulnerability is given a
<a href="security-impact.html">security impact rating</a> by the Apache
Tomcat security team &mdash; please note that this rating may vary from
platform to platform. We also list the versions of Apache Tomcat the flaw
is known to affect, and where a flaw has not been verified list the
version with a question mark.</p>
<p><strong>Please note that Tomcat 3 is no longer supported. Further
vulnerabilities in the 3.x branches will not be fixed. Users should upgrade
to 9.0.x or later to obtain security fixes.</strong></p>
<p>The published CVE records for vulnerabilities reported from 2023 onwards
include affected version information for EOL versions. By default, the
status for EOL versions is reported as unknown. <strong>Where additional
information is available, the published CVE record may be updated to
indicate whether an EOL version is affected / not-affected. Only the
published CVE record will be updated. This page will NOT be updated if
the status of an EOL version is updated. No email announcement will be
made if if the status of an EOL version is updated.</strong></p>
<p>Please send comments or corrections for these vulnerabilities to the
<a href="security.html">Tomcat Security Team</a>.</p>
</div><h3 id="Table_of_Contents">Table of Contents</h3><div class="text">
<ul><li><a href="#Not_fixed_in_Apache_Tomcat_3.x">Not fixed in Apache Tomcat 3.x</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.3.2">Fixed in Apache Tomcat 3.3.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.3.1a">Fixed in Apache Tomcat 3.3.1a</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.3.1">Fixed in Apache Tomcat 3.3.1</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.3a">Fixed in Apache Tomcat 3.3a</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.2.4">Fixed in Apache Tomcat 3.2.4</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.2.2">Fixed in Apache Tomcat 3.2.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.2">Fixed in Apache Tomcat 3.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.1">Fixed in Apache Tomcat 3.1</a></li></ul>
</div><h3 id="Not_fixed_in_Apache_Tomcat_3.x">Not fixed in Apache Tomcat 3.x</h3><div class="text">
<p><strong>Important: Denial of service</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0808" rel="nofollow">CVE-2005-0808</a></p>
<p>Tomcat 3.x can be remotely caused to crash or shutdown by a connection
sending the right sequence of bytes to the AJP12 protocol port (TCP 8007
by default). Tomcat 3.x users are advised to ensure that this port is
adequately firewalled to ensure it is not accessible to remote attackers.
There are no plans to issue a an update to Tomcat 3.x for this issue.</p>
<p>Affects: 3.0, 3.1-3.1.1, 3.2-3.2.4, 3.3a-3.3.2</p>
<p><strong>Low: Session hi-jacking</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3382" rel="nofollow">CVE-2007-3382</a></p>
<p>Tomcat incorrectly treated a single quote character (') in a cookie
value as a delimiter. In some circumstances this lead to the leaking of
information such as session ID to an attacker.</p>
<p>Affects: 3.3-3.3.2</p>
<p><strong>Low: Cross site scripting</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3384" rel="nofollow">CVE-2007-3384</a></p>
<p>When reporting error messages, Tomcat does not filter user supplied data
before display. This enables an XSS attack. A source patch is available
from the <a href="https://archive.apache.org/dist/tomcat/tomcat-3/v3.3.2-patches/src/">
archives</a>.</p>
<p>Affects: 3.3-3.3.2</p>
<p><strong>Low: Session hi-jacking</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3385" rel="nofollow">CVE-2007-3385</a></p>
<p>Tomcat incorrectly handled the character sequence \" in a cookie value.
In some circumstances this lead to the leaking of information such as
session ID to an attacker.</p>
<p>Affects: 3.3-3.3.2</p>
</div><h3 id="Fixed_in_Apache_Tomcat_3.3.2">Fixed in Apache Tomcat 3.3.2</h3><div class="text">
<p><strong>Moderate: Cross site scripting</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0044" rel="nofollow">CVE-2003-0044</a></p>
<p>The root web application and the examples web application contained a
number a cross-site scripting vulnerabilities. Note that is it
recommended that the examples web application is not installed on
production servers.</p>
<p>Affects: 3.0, 3.1-3.1.1, 3.2-3.2.4, 3.3a-3.3.1a</p>
</div><h3 id="Fixed_in_Apache_Tomcat_3.3.1a">Fixed in Apache Tomcat 3.3.1a</h3><div class="text">
<p><strong>Important: Information disclosure</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0043" rel="nofollow">CVE-2003-0043</a></p>
<p>When used with JDK 1.3.1 or earlier, web.xml files were read with
trusted privileges enabling files outside of the web application to be
read even when running under a security manager.</p>
<p>Affects: 3.0, 3.1-3.1.1, 3.2-3.2.4, 3.3a-3.3.1</p>
<p><strong>Important: Information disclosure</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0042" rel="nofollow">CVE-2003-0042</a></p>
<p>URLs containing null characters could result in file contents being
returned or a directory listing being returned even when a welcome file
was defined.</p>
<p>Affects: 3.0, 3.1-3.1.1, 3.2-3.2.4, 3.3a-3.3.1</p>
</div><h3 id="Fixed_in_Apache_Tomcat_3.3.1">Fixed in Apache Tomcat 3.3.1</h3><div class="text">
<p><strong>Important: Denial of service</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0045" rel="nofollow">CVE-2003-0045</a></p>
<p>JSP page names that match a Windows DOS device name, such as aux.jsp, may
cause the thread processing the request to become unresponsive. A
sequence of such requests may cause all request processing threads, and
hence Tomcat, to become unresponsive.</p>
<p>Affects: 3.0, 3.1-3.1.1, 3.2-3.2.4, 3.3a</p>
</div><h3 id="Fixed_in_Apache_Tomcat_3.3a">Fixed in Apache Tomcat 3.3a</h3><div class="text">
<p><strong>Moderate: Information disclosure</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2007" rel="nofollow">CVE-2002-2007</a></p>
<p>Non-standard requests to the sample applications installed by default
could result in unexpected directory listings or disclosure of the full
file system path for a JSP.</p>
<p>Affects: 3.2.3-3.2.4</p>
<p><strong>Low: Information disclosure</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2006" rel="nofollow">CVE-2002-2006</a>,
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0760" rel="nofollow">CVE-2000-0760</a></p>
<p>The snoop servlet installed as part of the examples includes output that
identifies the Tomcat installation path. There are no plans to issue a an
update to Tomcat 3.x for this issue.</p>
<p>Affects:3.1-3.1.1, 3.2-3.2.4</p>
</div><h3 id="Fixed_in_Apache_Tomcat_3.2.4">Fixed in Apache Tomcat 3.2.4</h3><div class="text">
<p><strong>Moderate: Information disclosure</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1563" rel="nofollow">CVE-2001-1563</a><br></p>
<p>No specifics are provided in the vulnerability report. This may be a
summary of other issues reported against 3.2.x</p>
<p>Affects: 3.2?, 3.2.1, 3.2.2-3.2.3?</p>
</div><h3 id="Fixed_in_Apache_Tomcat_3.2.2">Fixed in Apache Tomcat 3.2.2</h3><div class="text">
<p><strong>Moderate: Cross site scripting</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0829" rel="nofollow">CVE-2001-0829</a></p>
<p>The default 404 error page does not escape URLs. This allows XSS
attacks using specially crafted URLs.</p>
<p>Affects: 3.0, 3.1-3.1.1, 3.2-3.2.1</p>
<p><strong>Moderate: Information disclosure</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0590" rel="nofollow">CVE-2001-0590</a></p>
<p>A specially crafted URL can be used to obtain the source for JSPs.</p>
<p>Affects: 3.0, 3.1-3.1.1, 3.2-3.2.1</p>
</div><h3 id="Fixed_in_Apache_Tomcat_3.2">Fixed in Apache Tomcat 3.2</h3><div class="text">
<p><strong>Low: Information disclosure</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0759" rel="nofollow">CVE-2000-0759</a></p>
<p>Requesting a JSP that does not exist results in an error page that
includes the full file system page of the current context.</p>
<p>Affects: 3.1</p>
<p><strong>Important: Information disclosure</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0672" rel="nofollow">CVE-2000-0672</a></p>
<p>Access to the admin context is not protected. This context allows an
attacker to mount an arbitary file system path as a context. Any files
accessible from this file sytem path to the account under which Tomcat
is running are then visible to the attacker.</p>
<p>Affects: 3.1</p>
</div><h3 id="Fixed_in_Apache_Tomcat_3.1">Fixed in Apache Tomcat 3.1</h3><div class="text">
<p><strong>Important: Information disclosure</strong>
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1210" rel="nofollow">CVE-2000-1210</a></p>
<p>source.jsp, provided as part of the examples, allows an attacker to read
arbitrary files via a .. (dot dot) in the argument to source.jsp.</p>
<p>Affects: 3.0</p>
</div></div></div></div></main><footer id="footer">
Copyright &copy; 1999-2026, The Apache Software Foundation
<br>
Apache Tomcat, Tomcat, Apache, the Apache Tomcat logo and the Apache logo
are either registered trademarks or trademarks of the Apache Software
Foundation.
</footer></div><script src="res/js/tomcat.js"></script></body></html>