5
CVE-2007-5366
- EPSS 0.19%
- Published 11.10.2007 10:17:00
- Last modified 09.04.2025 00:30:58
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
The Tomcat 4.1-based Servlet Service in Fujitsu Interstage Application Server 7.0 through 9.0.0 and Interstage Apworks/Studio 7.0 through 9.0.0 allows remote attackers to obtain sensitive information (web root path) via unspecified vectors that trigger an error message, probably related to enabling the useCanonCaches Java Virtual Machine (JVM) option.
Data is provided by the National Vulnerability Database (NVD)
Fujitsu ≫ Interstage Application Server Version7.0 Editionenterprise
Fujitsu ≫ Interstage Application Server Version7.0 Editionplus
Fujitsu ≫ Interstage Application Server Version7.0 Editionplus_developer
Fujitsu ≫ Interstage Application Server Version7.0.1 Editionenterprise
Fujitsu ≫ Interstage Application Server Version7.0.1 Editionplus
Fujitsu ≫ Interstage Application Server Version8.0.0 Editionenterprise
Fujitsu ≫ Interstage Application Server Version8.0.0 Editionstandard_j
Fujitsu ≫ Interstage Application Server Version8.0.1 Editionenterprise
Fujitsu ≫ Interstage Application Server Version8.0.1 Editionstandard_j
Fujitsu ≫ Interstage Application Server Version8.0.2 Editionenterprise
Fujitsu ≫ Interstage Application Server Version8.0.2 Editionstandard_j
Fujitsu ≫ Interstage Application Server Version8.0.3 Editionenterprise
Fujitsu ≫ Interstage Application Server Version8.0.3 Editionstandard_j
Fujitsu ≫ Interstage Application Server Version9.0 Editionenterprise
Fujitsu ≫ Interstage Application Server Version9.0 Editionstandard_j
Fujitsu ≫ Interstage Application Server Version9.0a Editionenterprise
Fujitsu ≫ Interstage Application Server Version9.0a Editionstandard_j
Fujitsu ≫ Interstage Apworks Version7.0 Editionmodelers_j
Fujitsu ≫ Interstage Apworks Version8.0 Editionenterprise
Fujitsu ≫ Interstage Apworks Version8.0 Editionstandard_j
Fujitsu ≫ Interstage Studio Version8.01 Editionenterprise
Fujitsu ≫ Interstage Studio Version8.01 Editionstandard_j
Fujitsu ≫ Interstage Studio Version9.0 Editionenterprise
Fujitsu ≫ Interstage Studio Version9.0 Editionstandard_j
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.19% | 0.38 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.