CVE-2002-0493
Apache Tomcat may be started without proper security settings
EPSS 1.4%
Description
Apache Tomcat may be started without proper security settings if errors are encountered while reading the `web.xml` file, which could allow attackers to bypass intended restrictions.
How to fix CVE-2002-0493
To remediate CVE-2002-0493, upgrade the affected package to a fixed version below.
- Maven/org.apache.tomcat:tomcat—upgrade to 4.0b7 or later
Is CVE-2002-0493 being exploited?
Low — EPSS is 1.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.0b7