CVE-2015-5174

MEDIUM

Apache Tomcat < 8.0.27 - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application in a getResource, getResourceAsStream, or getResourcePaths call, as demonstrated by the $CATALINA_BASE/webapps directory.

References (47)

... and 27 more

Scores

CVSS v3 4.3
EPSS 0.0369
EPSS Percentile 87.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-22
Status draft

Affected Products (50)

apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
debian/debian_linux
debian/debian_linux
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
... and 35 more

Timeline

Published Feb 25, 2016
Tracked Since Feb 18, 2026