CVE-2006-3835
Apache Tomcat Reveals Directories
EPSS 45.6%
Description
Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (`;`) preceding a filename with a mapped extension, as demonstrated by URLs ending with `/;index.jsp` and `/;help.do`.
How to fix CVE-2006-3835
To remediate CVE-2006-3835, upgrade the affected package to a fixed version below.
- Maven/org.apache.tomcat:tomcat—upgrade to 5.5.17 or later
Is CVE-2006-3835 being exploited?
Moderate — EPSS is 45.6%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 5.0.0, < 5.5.17