CVE-2008-2938

Apache Tomcat 4.1.0-4.1.37, 5.5.0-5.5.26, 6.0.0-6.0.16 - Directory Traversal via Encoded URI Sequences

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 5 public exploits for CVE-2008-2938. PoCs published by mywisdom, Simon Ryeo, Naramsim, including Metasploit module auxiliary/admin/http/tomcat_utf8_traversal.

AI-analyzed exploit summary This exploit targets a directory traversal vulnerability in Apache Tomcat versions prior to 6.0.18 by sending a malformed UTF-8 encoded HTTP GET request to retrieve the contents of /etc/passwd. The code checks for the presence of 'root:x' to confirm successful exploitation.

Description

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.

Exploits (5)

exploitdb WORKING POC VERIFIED
by mywisdom · cremoteunix
https://www.exploit-db.com/exploits/14489

This exploit targets a directory traversal vulnerability in Apache Tomcat versions prior to 6.0.18 by sending a malformed UTF-8 encoded HTTP GET request to retrieve the contents of /etc/passwd. The code checks for the presence of 'root:x' to confirm successful exploitation.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Apache Tomcat < 6.0.18
No auth needed
Prerequisites: Network access to the target Tomcat server · Tomcat server running on port 80
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Simon Ryeo · textremotemultiple
https://www.exploit-db.com/exploits/6229

This exploit demonstrates a directory traversal vulnerability in Apache Tomcat prior to 6.0.18. By crafting a specific URL with UTF-8 encoded sequences, an attacker can access arbitrary files on the system.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Apache Tomcat prior to 6.0.18
No auth needed
Prerequisites: Tomcat configured with 'allowLinking' and 'URIencoding' set to UTF-8
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 1 stars
by Naramsim · poc
https://github.com/Naramsim/Offensive

The repository contains descriptions and references for multiple CVEs, including CVE-2014-2064, but lacks executable exploit code for the specified CVE. It includes detailed explanations and references for vulnerabilities in Tomcat, Spring, and Jenkins.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: Jenkins
No auth needed
Prerequisites: Access to the vulnerable Jenkins instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC
by aushack, guerrino <ruggine> di massa · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/tomcat_utf8_traversal.rb

This Metasploit module exploits a directory traversal vulnerability in Apache Tomcat (CVE-2008-2938) by sending UTF-8 encoded traversal sequences to access sensitive files. It tests for the vulnerability under specific configurations where allowLinking and URIEncoding are set in a non-default manner.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Apache Tomcat 4.1.0-4.1.37, 5.5.0-5.5.26, 6.0.0-6.0.16 with Java versions prior to Sun 1.4.2_19, 1.5.0_17, 6u11 or IBM Java 5.0 SR9, 1.4.2 SR13, SE 6 SR4
No auth needed
Prerequisites: Tomcat with allowLinking=true and URIEncoding=UTF-8 · Vulnerable Java version · Access to sensitive file paths
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC
by aushack · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/trendmicro_dlp_traversal.rb

This Metasploit module exploits a directory traversal vulnerability in Trend Micro DLP Appliance v5.5 build <= 1294, leveraging the Tomcat UTF-8 bug (CVE-2008-2938) to access sensitive files. It tests for the vulnerability by attempting to traverse directories and read files listed in a wordlist.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Trend Micro Data Loss Prevention Appliance v5.5 build <= 1294
No auth needed
Prerequisites: Network access to the target system · SSL enabled on port 8443
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (43)

Core 43
Core References
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-4.html
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37297
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-0862.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2823
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31982
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31681
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32120
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/343355
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/44411
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31865
Third Party Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00889.html
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31639
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1020665
Third Party Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2008:188
Third Party Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2008-401.htm
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0320
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-0864.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2343
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6229
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-6.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30633
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/507729/100/0/threaded
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32222
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31891
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33797
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4148
Third Party Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00712.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/495318/100/0/threaded
Third Party Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00859.html
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-5.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2780
Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=123376588623823&w=2
Mailing List, Third Party Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT3216
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32266
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-0648.html

Scores

EPSS 0.9282
EPSS Percentile 99.8%

Details

CWE
CWE-22
Status published
Products (2)
apache/tomcat 4.0.0 - 4.1.37
org.apache.tomcat/tomcat 4.1.0 - 4.1.39Maven
Published Aug 13, 2008
Tracked Since Feb 18, 2026