| <!DOCTYPE html SYSTEM "about:legacy-compat"> |
| <html lang="en"><head><META http-equiv="Content-Type" content="text/html; charset=UTF-8"><meta name="viewport" content="width=device-width, initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" type="text/css"><title>Apache Tomcat® - Apache Tomcat 3.x vulnerabilities</title><meta name="author" content="Apache Tomcat Project"><script src="https://www.apachecon.com/event-images/snippet.js"></script></head><body><div id="wrapper"><header id="header"><div class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div class="hamburger"></div></div><a href="http://tomcat.apache.org/"><img class="tomcat-logo pull-left noPrint" alt="Tomcat Home" src="res/images/tomcat.png"></a><h1 class="pull-left">Apache Tomcat<sup>®</sup></h1><div class="asf-logos pull-right"><a href="https://www.apache.org/foundation/contributing.html" target="_blank" class="pull-left"><img src="https://www.apache.org/images/SupportApache-small.png" class="support-asf" alt="Support Apache"></a><a href="http://www.apache.org/" target="_blank" class="pull-left"><img src="res/images/asf_logo_wide.svg" class="asf-logo" alt="The Apache Software Foundation"></a></div></div></header><main id="middle"><div><div id="mainLeft"><div id="nav-wrapper"><form action="https://www.google.com/search" method="get"><div class="searchbox"><input value="tomcat.apache.org" name="sitesearch" type="hidden"><input aria-label="Search text" placeholder="Search…" required="required" name="q" id="query" type="search"><button>GO</button></div></form><div class="asfevents"><a class="acevent" data-format="square" data-width="150"></a></div><nav><div><h2>Apache Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a href="./whichversion.html">Which version?</a></li><li><a href="https://tomcat.apache.org/download-11.cgi">Tomcat 11</a></li><li><a href="https://tomcat.apache.org/download-10.cgi">Tomcat 10</a></li><li><a href="https://tomcat.apache.org/download-90.cgi">Tomcat 9</a></li><li><a href="https://tomcat.apache.org/download-migration.cgi">Tomcat Migration Tool for Jakarta EE</a></li><li><a href="https://tomcat.apache.org/download-connectors.cgi">Tomcat Connectors</a></li><li><a href="https://tomcat.apache.org/download-native.cgi">Tomcat Native</a></li><li><a href="https://tomcat.apache.org/download-taglibs.cgi">Taglibs</a></li><li><a href="https://archive.apache.org/dist/tomcat/">Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a href="./tomcat-11.0-doc/index.html">Tomcat 11.0</a></li><li><a href="./tomcat-10.1-doc/index.html">Tomcat 10.1</a></li><li><a href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a href="./upgrading.html">Upgrading</a></li><li><a href="./connectors-doc/index.html">Tomcat Connectors</a></li><li><a href="./native-doc/index.html">Tomcat Native 2</a></li><li><a href="./native-1.3-doc/index.html">Tomcat Native 1.3</a></li><li><a href="https://cwiki.apache.org/confluence/display/TOMCAT">Wiki</a></li><li><a href="./migration.html">Migration Guide</a></li><li><a href="./presentations.html">Presentations</a></li><li><a href="https://cwiki.apache.org/confluence/x/Bi8lBg">Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a href="./security.html">Security Reports</a></li><li><a href="./findhelp.html">Find help</a></li><li><a href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ">FAQ</a></li><li><a href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug Database</a></li></ul></div><div><h2>Get Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a href="./source.html">Source code</a></li><li><a href="./ci.html">Buildbot</a></li><li><a href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a href="https://www.youtube.com/c/ApacheTomcatOfficial">YouTube</a></li></ul></div><div><h2>Misc</h2><ul><li><a href="./whoweare.html">Who We Are</a></li><li><a href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat">Swag</a></li><li><a href="./heritage.html">Heritage</a></li><li><a href="http://www.apache.org">Apache Home</a></li><li><a href="./resources.html">Resources</a></li><li><a href="./contact.html">Contact</a></li><li><a href="./legal.html">Legal</a></li><li><a href="https://privacy.apache.org/policies/privacy-policy-public.html">Privacy</a></li><li><a href="https://www.apache.org/foundation/contributing.html">Support Apache</a></li><li><a href="https://www.apache.org/foundation/sponsorship.html">Sponsorship</a></li><li><a href="http://www.apache.org/foundation/thanks.html">Thanks</a></li><li><a href="http://www.apache.org/licenses/">License</a></li></ul></div></nav></div></div><div id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 id="Apache_Tomcat_3.x_vulnerabilities">Apache Tomcat 3.x vulnerabilities</h3><div class="text"> |
| <p>This page lists all security vulnerabilities fixed in released versions |
| of Apache Tomcat<sup>®</sup> 3.x. Each vulnerability is given a |
| <a href="security-impact.html">security impact rating</a> by the Apache |
| Tomcat security team — please note that this rating may vary from |
| platform to platform. We also list the versions of Apache Tomcat the flaw |
| is known to affect, and where a flaw has not been verified list the |
| version with a question mark.</p> |
| |
| <p><strong>Please note that Tomcat 3 is no longer supported. Further |
| vulnerabilities in the 3.x branches will not be fixed. Users should upgrade |
| to 9.0.x or later to obtain security fixes.</strong></p> |
| |
| <p>The published CVE records for vulnerabilities reported from 2023 onwards |
| include affected version information for EOL versions. By default, the |
| status for EOL versions is reported as unknown. <strong>Where additional |
| information is available, the published CVE record may be updated to |
| indicate whether an EOL version is affected / not-affected. Only the |
| published CVE record will be updated. This page will NOT be updated if |
| the status of an EOL version is updated. No email announcement will be |
| made if if the status of an EOL version is updated.</strong></p> |
| |
| <p>Please send comments or corrections for these vulnerabilities to the |
| <a href="security.html">Tomcat Security Team</a>.</p> |
| |
| </div><h3 id="Table_of_Contents">Table of Contents</h3><div class="text"> |
| <ul><li><a href="#Not_fixed_in_Apache_Tomcat_3.x">Not fixed in Apache Tomcat 3.x</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.3.2">Fixed in Apache Tomcat 3.3.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.3.1a">Fixed in Apache Tomcat 3.3.1a</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.3.1">Fixed in Apache Tomcat 3.3.1</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.3a">Fixed in Apache Tomcat 3.3a</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.2.4">Fixed in Apache Tomcat 3.2.4</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.2.2">Fixed in Apache Tomcat 3.2.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.2">Fixed in Apache Tomcat 3.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_3.1">Fixed in Apache Tomcat 3.1</a></li></ul> |
| </div><h3 id="Not_fixed_in_Apache_Tomcat_3.x">Not fixed in Apache Tomcat 3.x</h3><div class="text"> |
| <p><strong>Important: Denial of service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0808" rel="nofollow">CVE-2005-0808</a></p> |
| |
| <p>Tomcat 3.x can be remotely caused to crash or shutdown by a connection |
| sending the right sequence of bytes to the AJP12 protocol port (TCP 8007 |
| by default). Tomcat 3.x users are advised to ensure that this port is |
| adequately firewalled to ensure it is not accessible to remote attackers. |
| There are no plans to issue a an update to Tomcat 3.x for this issue.</p> |
| |
| <p>Affects: 3.0, 3.1-3.1.1, 3.2-3.2.4, 3.3a-3.3.2</p> |
| |
| <p><strong>Low: Session hi-jacking</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3382" rel="nofollow">CVE-2007-3382</a></p> |
| |
| <p>Tomcat incorrectly treated a single quote character (') in a cookie |
| value as a delimiter. In some circumstances this lead to the leaking of |
| information such as session ID to an attacker.</p> |
| |
| <p>Affects: 3.3-3.3.2</p> |
| |
| <p><strong>Low: Cross site scripting</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3384" rel="nofollow">CVE-2007-3384</a></p> |
| |
| <p>When reporting error messages, Tomcat does not filter user supplied data |
| before display. This enables an XSS attack. A source patch is available |
| from the <a href="https://archive.apache.org/dist/tomcat/tomcat-3/v3.3.2-patches/src/"> |
| archives</a>.</p> |
| |
| <p>Affects: 3.3-3.3.2</p> |
| |
| <p><strong>Low: Session hi-jacking</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3385" rel="nofollow">CVE-2007-3385</a></p> |
| |
| <p>Tomcat incorrectly handled the character sequence \" in a cookie value. |
| In some circumstances this lead to the leaking of information such as |
| session ID to an attacker.</p> |
| |
| <p>Affects: 3.3-3.3.2</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_3.3.2">Fixed in Apache Tomcat 3.3.2</h3><div class="text"> |
| <p><strong>Moderate: Cross site scripting</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0044" rel="nofollow">CVE-2003-0044</a></p> |
| |
| <p>The root web application and the examples web application contained a |
| number a cross-site scripting vulnerabilities. Note that is it |
| recommended that the examples web application is not installed on |
| production servers.</p> |
| |
| <p>Affects: 3.0, 3.1-3.1.1, 3.2-3.2.4, 3.3a-3.3.1a</p> |
| </div><h3 id="Fixed_in_Apache_Tomcat_3.3.1a">Fixed in Apache Tomcat 3.3.1a</h3><div class="text"> |
| <p><strong>Important: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0043" rel="nofollow">CVE-2003-0043</a></p> |
| |
| <p>When used with JDK 1.3.1 or earlier, web.xml files were read with |
| trusted privileges enabling files outside of the web application to be |
| read even when running under a security manager.</p> |
| |
| <p>Affects: 3.0, 3.1-3.1.1, 3.2-3.2.4, 3.3a-3.3.1</p> |
| |
| <p><strong>Important: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0042" rel="nofollow">CVE-2003-0042</a></p> |
| |
| <p>URLs containing null characters could result in file contents being |
| returned or a directory listing being returned even when a welcome file |
| was defined.</p> |
| |
| <p>Affects: 3.0, 3.1-3.1.1, 3.2-3.2.4, 3.3a-3.3.1</p> |
| </div><h3 id="Fixed_in_Apache_Tomcat_3.3.1">Fixed in Apache Tomcat 3.3.1</h3><div class="text"> |
| <p><strong>Important: Denial of service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0045" rel="nofollow">CVE-2003-0045</a></p> |
| |
| <p>JSP page names that match a Windows DOS device name, such as aux.jsp, may |
| cause the thread processing the request to become unresponsive. A |
| sequence of such requests may cause all request processing threads, and |
| hence Tomcat, to become unresponsive.</p> |
| |
| <p>Affects: 3.0, 3.1-3.1.1, 3.2-3.2.4, 3.3a</p> |
| </div><h3 id="Fixed_in_Apache_Tomcat_3.3a">Fixed in Apache Tomcat 3.3a</h3><div class="text"> |
| <p><strong>Moderate: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2007" rel="nofollow">CVE-2002-2007</a></p> |
| |
| <p>Non-standard requests to the sample applications installed by default |
| could result in unexpected directory listings or disclosure of the full |
| file system path for a JSP.</p> |
| |
| <p>Affects: 3.2.3-3.2.4</p> |
| |
| <p><strong>Low: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2006" rel="nofollow">CVE-2002-2006</a>, |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0760" rel="nofollow">CVE-2000-0760</a></p> |
| |
| <p>The snoop servlet installed as part of the examples includes output that |
| identifies the Tomcat installation path. There are no plans to issue a an |
| update to Tomcat 3.x for this issue.</p> |
| |
| <p>Affects:3.1-3.1.1, 3.2-3.2.4</p> |
| </div><h3 id="Fixed_in_Apache_Tomcat_3.2.4">Fixed in Apache Tomcat 3.2.4</h3><div class="text"> |
| <p><strong>Moderate: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1563" rel="nofollow">CVE-2001-1563</a><br></p> |
| |
| <p>No specifics are provided in the vulnerability report. This may be a |
| summary of other issues reported against 3.2.x</p> |
| |
| <p>Affects: 3.2?, 3.2.1, 3.2.2-3.2.3?</p> |
| </div><h3 id="Fixed_in_Apache_Tomcat_3.2.2">Fixed in Apache Tomcat 3.2.2</h3><div class="text"> |
| <p><strong>Moderate: Cross site scripting</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0829" rel="nofollow">CVE-2001-0829</a></p> |
| |
| <p>The default 404 error page does not escape URLs. This allows XSS |
| attacks using specially crafted URLs.</p> |
| |
| <p>Affects: 3.0, 3.1-3.1.1, 3.2-3.2.1</p> |
| |
| <p><strong>Moderate: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0590" rel="nofollow">CVE-2001-0590</a></p> |
| |
| <p>A specially crafted URL can be used to obtain the source for JSPs.</p> |
| |
| <p>Affects: 3.0, 3.1-3.1.1, 3.2-3.2.1</p> |
| </div><h3 id="Fixed_in_Apache_Tomcat_3.2">Fixed in Apache Tomcat 3.2</h3><div class="text"> |
| <p><strong>Low: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0759" rel="nofollow">CVE-2000-0759</a></p> |
| |
| <p>Requesting a JSP that does not exist results in an error page that |
| includes the full file system page of the current context.</p> |
| |
| <p>Affects: 3.1</p> |
| |
| <p><strong>Important: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0672" rel="nofollow">CVE-2000-0672</a></p> |
| |
| <p>Access to the admin context is not protected. This context allows an |
| attacker to mount an arbitary file system path as a context. Any files |
| accessible from this file sytem path to the account under which Tomcat |
| is running are then visible to the attacker.</p> |
| |
| <p>Affects: 3.1</p> |
| </div><h3 id="Fixed_in_Apache_Tomcat_3.1">Fixed in Apache Tomcat 3.1</h3><div class="text"> |
| <p><strong>Important: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1210" rel="nofollow">CVE-2000-1210</a></p> |
| |
| <p>source.jsp, provided as part of the examples, allows an attacker to read |
| arbitrary files via a .. (dot dot) in the argument to source.jsp.</p> |
| |
| <p>Affects: 3.0</p> |
| </div></div></div></div></main><footer id="footer"> |
| Copyright © 1999-2026, The Apache Software Foundation |
| <br> |
| Apache Tomcat, Tomcat, Apache, the Apache Tomcat logo and the Apache logo |
| are either registered trademarks or trademarks of the Apache Software |
| Foundation. |
| </footer></div><script src="res/js/tomcat.js"></script></body></html> |