CVE-2009-0783
MEDIUMApache Tomcat <6.0.19 - Info Disclosure
Title source: llmDescription
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.
References (47)
... and 27 more
Scores
CVSS v3
4.2
EPSS
0.0010
EPSS Percentile
27.1%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-200
Status
draft
Affected Products (2)
apache/tomcat
< 4.1.39
org.apache.tomcat/tomcat
Maven
Timeline
Published
Jun 05, 2009
Tracked Since
Feb 18, 2026