5

CVE-2005-1754

Exploit

JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter.  NOTE: Sun and Apache dispute this issue.  Sun states: "The report makes references to source code and files that do not exist in the mentioned products.

Data is provided by the National Vulnerability Database (NVD)
Apache TomcatApache Tomcat Version5.0.16
SunJavamail Version1.1.3
SunJavamail Version1.2
SunJavamail Version1.3
SunJavamail Version1.3.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 8.85% 0.923
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.