CVE-2009-0783
tomcat XML parser information disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.
Apache Tomcat v4.1.0 hasta la v4.1.39, v5.5.0 hasta la v5.5.27 y v6.0.0 hasta la v6.0.18 permite a las aplicaciones web reemplazar un "parser" (extractor de información) XML utilizado por otras aplicaciones web, lo que permite a los usuarios locales leer o modificar los ficheros (1) web.xml, (2) context.xml o (3) ficheros tld de aplicaciones web de su elección a través de una aplicacion manipulada que es cargada antes de la aplicación web objetivo del ataque.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-03-04 CVE Reserved
- 2009-06-05 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (49)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://svn.apache.org/viewvc?rev=652592&view=rev | 2023-02-13 | |
http://svn.apache.org/viewvc?rev=681156&view=rev | 2023-02-13 | |
http://svn.apache.org/viewvc?rev=739522&view=rev | 2023-02-13 | |
http://svn.apache.org/viewvc?rev=781542&view=rev | 2023-02-13 | |
http://svn.apache.org/viewvc?rev=781708&view=rev | 2023-02-13 | |
http://tomcat.apache.org/security-4.html | 2023-02-13 | |
http://tomcat.apache.org/security-5.html | 2023-02-13 | |
http://tomcat.apache.org/security-6.html | 2023-02-13 | |
https://issues.apache.org/bugzilla/show_bug.cgi?id=29936 | 2023-02-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | >= 4.1.0 <= 4.1.39 Search vendor "Apache" for product "Tomcat" and version " >= 4.1.0 <= 4.1.39" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | >= 5.5.0 <= 5.5.27 Search vendor "Apache" for product "Tomcat" and version " >= 5.5.0 <= 5.5.27" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | >= 6.0.0 <= 6.0.18 Search vendor "Apache" for product "Tomcat" and version " >= 6.0.0 <= 6.0.18" | - |
Affected
|