CVE-2008-2938 is a directory traversal vulnerability affecting Apache Tomcat versions 4.1.0-4.1.37, 5.5.0-5.5.26, and 6.0.0-6.0.16. When allowLinking and UTF-8 are enabled, remote attackers can read arbitrary files using encoded directory traversal sequences in the URI. This vulnerability has a CVSS score of 4.3 (Medium), indicating it can be exploited remotely with medium complexity to achieve partial confidentiality impact. While not listed in CISA's KEV catalog, exploit code is publicly available via Metasploit and ExploitDB, and its EPSS score of 0.9282 suggests a high likelihood of exploitation. Despite this, there is no recorded community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, <= 4.1.37CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 5.0.0, <= 5.5.26CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 6.0.0, <= 6.0.16CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.