UNKNOWN Maven

Apache Tomcat Leaks Information via Error Message

GHSA-m8w6-7rh6-4xj6 · CVE-2002-2008

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the information in an error message.

Ready to move

Start Securing

Free, no credit card | First findings in minutes