CVE-2008-0002
Apache Tomcat Sensitive Information Disclosure
EPSS 5.1%
Description
Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.
How to fix CVE-2008-0002
To remediate CVE-2008-0002, upgrade the affected package to a fixed version below.
- Maven/org.apache.tomcat:tomcat—upgrade to 6.0.16 or later
Is CVE-2008-0002 being exploited?
Moderate — EPSS is 5.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 6.0.0, < 6.0.16