CVE-2009-0783
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
4.2
MEDIUM
CVSS 3.1
EPSS 0.10%
Description
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.
How to fix CVE-2009-0783
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- —no fix listed
Is CVE-2009-0783 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 4.1.0, <= 4.1.39
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.2 | CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L |