peter bassill · operator
$ cve CVE-2009-0580 JSON

CVE-2009-0580 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 94.4% (pctl 100)

Patch early

A public exploit exists.

Description

Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authentication realms, as demonstrated by a % (percent) value for the j_password parameter.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS94.44% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2009-06-05
Last modified2026-06-16

Affected (1)

VendorProduct
apachetomcat

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD