Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to 5.5.22Upgrade Apache Tomcat to 5.0.0Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 4.1.36Upgrade Apache Tomcat to 6.0.10 | May 17, 2012 | Mar 16, 2007 |
| Apple Osx Tomcat | — | Apply OS X security update 2007-007 | Dec 16, 2011 | Mar 16, 2007 |
| Freebsd | — | Upgrade tomcatUpgrade apache-tomcatUpgrade jakarta-tomcat | Dec 10, 2025 | Jul 24, 2007 |
| Gentoo Linux | — | Upgrade www-servers/tomcat. | Oct 30, 2017 | Mar 16, 2007 |
| Oracle_linux | — | Upgrade tomcat5-jsp-2.0-apiUpgrade tomcat5Upgrade tomcat5-server-libUpgrade tomcat5-admin-webappsUpgrade tomcat5-jasperUpgrade tomcat5-webappsUpgrade tomcat5-jasper-javadocUpgrade tomcat5-common-libUpgrade tomcat5-servlet-2.4-api-javadocUpgrade tomcat5-servlet-2.4-apiUpgrade tomcat5-jsp-2.0-api-javadocUpgrade jakarta-commons-modelerUpgrade jakarta-commons-modeler-javadoc | Oct 16, 2024 | Mar 16, 2007 |
| Suse | — | Upgrade jakarta-tomcatUpgrade tomcat5Upgrade tomcat5-admin-webappsUpgrade tomcat5-webappsUpgrade suse-release | Feb 17, 2015 | Mar 16, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub