CVE-2001-0590
Apache Tomcat Allows Source Disclosure
EPSS 11.0%
Description
Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).
How to fix CVE-2001-0590
To remediate CVE-2001-0590, upgrade the affected package to a fixed version below.
- Maven/org.apache.tomcat:tomcat-servlet-api—upgrade to 3.2.2 or later
Is CVE-2001-0590 being exploited?
Moderate — EPSS is 11.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 3.2.2