← Back

CVE-2005-4836

nvd nist
Published: Dec 31, 2005Modified: Apr 16, 2026

JSON object

Loading...
7.8
Vector
AV:N/AC:L/Au:N/C:C/I:N/A:N
Exploitability: 10.0 / Impact: 6.9
Source: NVD

Description

The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.

Affected (26)

Products: Apache: Tomcat
1 product
Tomcat
Configuration A
26 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 4.1.15
Version 4.1.16
Version 4.1.17
Version 4.1.18
Version 4.1.19
Version 4.1.20
Version 4.1.21
Version 4.1.22
Version 4.1.23
Version 4.1.24
Version 4.1.25
Version 4.1.26
Version 4.1.27
Version 4.1.28 alpha
Version 4.1.29
Version 4.1.29 alpha
Version 4.1.30
Version 4.1.31
Version 4.1.32
Version 4.1.33
Version 4.1.34
Version 4.1.35
Version 4.1.36
Version 4.1.37
Version 4.1.39
Version 4.1.40

Timeline

No history available yet.