CVE-2015-5345
MEDIUMApache Tomcat <6.0.45-9.0.0.M2 - Info Disclosure
Title source: llmDescription
The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a directory via a URL that lacks a trailing / (slash) character.
References (51)
... and 31 more
Scores
CVSS v3
5.3
EPSS
0.1482
EPSS Percentile
94.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-22
Status
draft
Affected Products (50)
debian/debian_linux
debian/debian_linux
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
... and 35 more
Timeline
Published
Feb 25, 2016
Tracked Since
Feb 18, 2026