CVE-2007-5461 EXPLOIT
3.5
LOW · CVSS 2.0 · EPSS 39.7% (pctl 99)
Patch early
A public exploit exists.
Description
Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.
Scoring
| CVSS | 3.5 (LOW, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:S/C:P/I:N/A:N |
| EPSS | 39.68% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-10-15 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| apache | tomcat |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Apache Tomcat - WebDAV SSL Remote File Disclosure | 2007-10-21 |
| exploit-db | Apache Tomcat - 'WebDAV' Remote File Disclosure | 2007-10-14 |
References
- http://geronimo.apache.org/2007/10/18/potential-vulnerability-in-apache-tomcat-webdav-servlet.html
- http://issues.apache.org/jira/browse/GERONIMO-3549
- http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
- http://mail-archives.apache.org/mod_mbox/tomcat-users/200710.mbox/%3C47135C2D.1000705%40apache.org%3E
- http://marc.info/?l=bugtraq&m=139344343412337&w=2
- http://marc.info/?l=full-disclosure&m=119239530508382
- http://rhn.redhat.com/errata/RHSA-2008-0630.html
- http://secunia.com/advisories/27398
- http://secunia.com/advisories/27446
- http://secunia.com/advisories/27481
- http://secunia.com/advisories/27727
- http://secunia.com/advisories/28317
- http://secunia.com/advisories/28361
- http://secunia.com/advisories/29242
- http://secunia.com/advisories/29313
- http://secunia.com/advisories/29711
- http://secunia.com/advisories/30676
→ the Explorer · watch your stack · NVD