Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-0450

75
FAUCET Score

CVE-2007-0450 describes a directory traversal vulnerability affecting Apache HTTP Server and Tomcat versions 5.x before 5.5.22 and 6.x before 6.0.10, specifically when using proxy modules like mod_proxy, mod_rewrite, or mod_jk. Attackers can exploit this by crafting URLs with “..” sequences combined with various slash and backslash characters, which Tomcat interprets differently than Apache, leading to unauthorized file access. The vulnerability has a CVSS score of 5.0, indicating a medium severity with low attack complexity and no authentication required, potentially allowing remote attackers to read arbitrary files. While not listed on CISA’s KEV catalog, an exploit is available on ExploitDB, and its EPSS score suggests a high probability of exploitation. Despite this, there is no recorded community discussion or media coverage, indicating low public awareness.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:apache:http_server:-:*:*:*:*:*:*:*
>= 5.0.0, < 5.5.22CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
>= 6.0.0, < 6.0.10CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
90.77%
Probability of exploitation in next 30 days
EPSS Percentile
99.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-29739 · Mar 14, 2007
This CVE's current EPSS score of 0.9077 is in the 100th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (81)

mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcatFixed in: 5.5.22
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcatFixed in: 6.0.10
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: ant-0:1.6.5-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: avalon-logkit-0:1.2-2jpp_4rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: axis-0:1.2.1-1jpp_3rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: classpathx-jaf-0:1.0-2jpp_6rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: classpathx-mail-0:1.1.1-2jpp_8rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: geronimo-specs-0:1.0-0.M4.1jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: jakarta-commons-modeler-0:2.0-3jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: log4j-0:1.2.12-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: mx4j-1:3.0.1-1jpp_4rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: pcsc-lite-0:1.3.3-3.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-ca-0:7.3.0-20.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-java-tools-0:7.3.0-10.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-kra-0:7.3.0-14.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-manage-0:7.3.0-19.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-native-tools-0:7.3.0-6.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-ocsp-0:7.3.0-13.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-tks-0:7.3.0-13.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: tomcat5-0:5.5.23-0jpp_4rh.16
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: xerces-j2-0:2.7.1-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: xml-commons-0:1.3.02-2jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Developer Suite V.3Fixed in: jakarta-commons-modeler-0:2.0-3jpp_3rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Developer Suite V.3Fixed in: tomcat5-0:5.5.23-0jpp_6rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: jakarta-commons-modeler-0:1.1-8jpp.1.0.2.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: tomcat5-0:5.5.23-0jpp.1.0.3.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.0Fixed in: jakarta-commons-pool-0:1.2-2jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.0Fixed in: tomcat5-0:5.0.30-0jpp_6rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.0Fixed in: tyrex-0:1.0.1-2jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.0 (RHEL3)Fixed in: jakarta-commons-pool-0:1.2-2jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.0 (RHEL3)Fixed in: tomcat5-0:5.0.30-0jpp_6rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.0 (RHEL3)Fixed in: tyrex-0:1.0.1-2jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.1Fixed in: jakarta-commons-pool-0:1.2-2jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.1Fixed in: tomcat5-0:5.0.30-0jpp_6rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.1Fixed in: tyrex-0:1.0.1-2jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.1 (RHEL3)Fixed in: jakarta-commons-pool-0:1.2-2jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.1 (RHEL3)Fixed in: tomcat5-0:5.0.30-0jpp_6rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.1 (RHEL3)Fixed in: tyrex-0:1.0.1-2jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: jakarta-commons-pool-0:1.2-2jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: tomcat5-0:5.0.30-0jpp_6rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: tyrex-0:1.0.1-2jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: jabberd-0:2.0s10-3.38.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: openmotif21-0:2.1.30-11.RHEL4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: perl-Crypt-CBC-0:2.24-1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-modjk-0:1.2.23-2rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-modperl-0:1.29-16.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-modssl-0:2.8.12-8.rhn.10.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: jakarta-commons-pool-0:1.2-2jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: tomcat5-0:5.0.30-0jpp_6rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: tyrex-0:1.0.1-2jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: jabberd-0:2.0s10-3.37.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: openmotif21-0:2.1.30-9.RHEL3.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: perl-Crypt-CBC-0:2.24-1.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-modjk-0:1.2.23-2rhn.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-modperl-0:1.29-16.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-modssl-0:2.8.12-8.rhn.10.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: jakarta-commons-pool-0:1.2-2jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: tomcat5-0:5.0.30-0jpp_6rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: tyrex-0:1.0.1-2jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: jabberd-0:2.0s10-3.38.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: openmotif21-0:2.1.30-11.RHEL4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: perl-Crypt-CBC-0:2.24-1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-modjk-0:1.2.23-2rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-modperl-0:1.29-16.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-modssl-0:2.8.12-8.rhn.10.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: jbossas-0:4.0.5-2.CP04.el4s1.2
View patch
redhatpatch availablevia redhat_api
Product: RHAPS Version 1 for RHEL 3Fixed in: tomcat5-0:5.0.30-0jpp_5rh
View patch
redhatpatch availablevia redhat_api
Product: RHAPS Version 2 for RHEL 4Fixed in: jakarta-commons-modeler-0:2.0-3jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: RHAPS Version 2 for RHEL 4Fixed in: tomcat5-0:5.5.23-0jpp_4rh.3
View patch

Vendor Advisories (2)

mavenGHSA-4prh-gqw8-rgh5medium

Apache Tomcat Directory Traversal

May 1, 2022
redhatCVE-2007-0450Important

tomcat directory traversal

Mar 14, 2007

References

community.ca.com / blogs/casecurityresponseblog/archive/2009/01/23.aspx
Broken Link
docs.info.apple.com / article.html
Third Party Advisory
h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
Broken Link
lists.apple.com / archives/security-announce//2007/Jul/msg00004.html
Mailing ListThird Party Advisory
lists.vmware.com / pipermail/security-announce/2008/000003.html
Third Party Advisory
secunia.com / advisories/24732
Third Party Advisory
secunia.com / advisories/25106
Third Party Advisory
secunia.com / advisories/25280
Third Party Advisory
secunia.com / advisories/26235
Third Party Advisory
secunia.com / advisories/26660
Third Party Advisory
secunia.com / advisories/27037
Third Party Advisory
secunia.com / advisories/28365
Third Party Advisory
secunia.com / advisories/30899
Third Party Advisory
secunia.com / advisories/30908
Third Party Advisory
secunia.com / advisories/33668
Third Party Advisory
security.gentoo.org / glsa/glsa-200705-03.xml
Third Party Advisory
securityreason.com / securityalert/2446
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/32988
Third Party AdvisoryVDB Entry
lists.apache.org / thread.html/277d42b48b6e9aef50949c0dcc79ce21693091d73da246b3c1981925%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/5b7a23e245c93235c503900da854a143596d901bf1a1f67e851a5de4%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/8d2a579bbd977c225c70cb23b0ec54865fb0dab5da3eff1e060c9935%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/r5c616dfc49156e4b06ffab842800c80f4425924d0f20c452c127a53c%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3E
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10643
Third Party Advisory
sunsolve.sun.com / search/document.do
Broken Link
support.avaya.com / elmodocs2/security/ASA-2007-206.htm
Third Party Advisory
support.ca.com / irj/portal/anonymous/phpsupcontent
Broken LinkThird Party Advisory
tomcat.apache.org / security-4.html
Vendor Advisory
tomcat.apache.org / security-5.html
Vendor Advisory
tomcat.apache.org / security-6.html
Vendor Advisory
fujitsu.com / global/support/software/security/products-f/interstage-200702e.html
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
novell.com / linux/security/advisories/2007_15_sr.html
Broken Link
novell.com / linux/security/advisories/2007_5_sr.html
Broken Link
redhat.com / support/errata/RHSA-2007-0327.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-0360.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0261.html
Third Party Advisory
sec-consult.com / 287.html
Broken Link
sec-consult.com / fileadmin/Advisories/20070314-0-apache_tomcat_directory_traversal.txt
Broken Link
securityfocus.com / archive/1/462791/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/485938/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/500396/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/500412/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/22960
Third Party AdvisoryVDB Entry
securityfocus.com / bid/25159
Third Party AdvisoryVDB Entry
vupen.com / english/advisories/2007/0975
Third Party Advisory
vupen.com / english/advisories/2007/2732
Third Party Advisory
vupen.com / english/advisories/2007/3087
Third Party Advisory
vupen.com / english/advisories/2007/3386
Third Party Advisory
vupen.com / english/advisories/2008/0065
Third Party Advisory
vupen.com / english/advisories/2008/1979/references
Third Party Advisory
vupen.com / english/advisories/2009/0233
Third Party Advisory