Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-5333

61
FAUCET Score

CVE-2007-5333 describes an information disclosure vulnerability in Apache Tomcat versions 6.0.0-6.0.14, 5.5.0-5.5.25, and 4.1.0-4.1.36. This flaw, stemming from an incomplete fix for CVE-2007-3385, allows sensitive information like session IDs to be leaked due to improper handling of double quotes or encoded backslashes in cookie values. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N), it represents a medium severity risk where an unauthenticated attacker can remotely exploit the vulnerability with low complexity to gain partial confidentiality. While not listed on the KEV catalog, an ExploitDB entry (EDB-31130) confirms the existence of public exploit code, though there is no evidence of active exploitation, Metasploit modules, Nuclei templates, or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.1.0, <= 4.1.36CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
>= 5.5.0, <= 5.5.25CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
>= 6.0.0, <= 6.0.14CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
62.58%
Probability of exploitation in next 30 days
EPSS Percentile
99.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-31130 · Feb 9, 2008
This CVE's current EPSS score of 0.6258 is in the 99th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (30)

mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcatFixed in: 6.0.15
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcatFixed in: 5.5.26
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcatFixed in: 4.1.37
redhatpatch availablevia redhat_api
Product: JBEWS 1.0 for RHEL 4Fixed in: tomcat5-0:5.5.23-1.patch07.19.ep5.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: ant-0:1.6.5-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: avalon-logkit-0:1.2-2jpp_4rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: axis-0:1.2.1-1jpp_3rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: classpathx-jaf-0:1.0-2jpp_6rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: classpathx-mail-0:1.1.1-2jpp_8rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: geronimo-specs-0:1.0-0.M4.1jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: jakarta-commons-modeler-0:2.0-3jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: log4j-0:1.2.12-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: mx4j-1:3.0.1-1jpp_4rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: pcsc-lite-0:1.3.3-3.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-ca-0:7.3.0-20.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-java-tools-0:7.3.0-10.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-kra-0:7.3.0-14.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-manage-0:7.3.0-19.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-native-tools-0:7.3.0-6.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-ocsp-0:7.3.0-13.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-tks-0:7.3.0-13.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: tomcat5-0:5.5.23-0jpp_4rh.16
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: xerces-j2-0:2.7.1-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: xml-commons-0:1.3.02-2jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Developer Suite V.3Fixed in: tomcat5-0:5.5.23-0jpp_18rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: tomcat5-0:5.5.23-0jpp.7.el5_3.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Web Server 1 for RHEL 5Fixed in: tomcat5-0:5.5.23-0jpp.9.6.ep5.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.2Fixed in: tomcat5-0:5.5.23-0jpp_18rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.3Fixed in: tomcat5-0:5.5.23-0jpp_18rh
View patch
redhatpatch availablevia redhat_api
Product: RHAPS Version 2 for RHEL 4Fixed in: tomcat5-0:5.5.23-0jpp_4rh.16
View patch

Vendor Advisories (2)

mavenGHSA-cww4-vj5r-rx57medium

Exposure of Sensitive Information in Apache Tomcat

May 1, 2022
redhatCVE-2007-5333Low

Improve cookie parsing for tomcat5

Feb 11, 2008

References

jvn.jp / jp/JVN%2309470767/index.html
Third Party AdvisoryVDB Entry
lists.apple.com / archives/security-announce/2008//Jun/msg00002.html
Mailing ListThird Party Advisory
lists.apple.com / archives/security-announce/2008/Oct/msg00001.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2009-02/msg00002.html
Third Party Advisory
marc.info
Mailing ListThird Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
secunia.com / advisories/28878
Broken Link
secunia.com / advisories/28884
Broken Link
secunia.com / advisories/28915
Broken Link
secunia.com / advisories/29711
Broken Link
secunia.com / advisories/30676
Broken Link
secunia.com / advisories/30802
Broken Link
secunia.com / advisories/32036
Broken Link
secunia.com / advisories/32222
Broken Link
secunia.com / advisories/33330
Broken Link
secunia.com / advisories/37460
Broken Link
secunia.com / advisories/44183
Broken Link
secunia.com / advisories/57126
Broken Link
security.gentoo.org / glsa/glsa-200804-10.xml
Broken Link
securityreason.com / securityalert/3636
Broken Link
lists.apache.org / thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11177
Tool Signature
support.apple.com / kb/HT2163
Third Party Advisory
support.apple.com / kb/HT3216
Third Party Advisory
redhat.com / archives/fedora-package-announce/2008-February/msg00315.html
Third Party Advisory
redhat.com / archives/fedora-package-announce/2008-February/msg00460.html
Third Party Advisory
tomcat.apache.org / security-4.html
Vendor Advisory
tomcat.apache.org / security-5.html
Vendor Advisory
tomcat.apache.org / security-6.html
Vendor Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-1.ibm.com / support/docview.wss
Third Party Advisory
www-1.ibm.com / support/docview.wss
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
redhat.com / docs/en-US/JBoss_Enterprise_Application_Platform/4.2.0.cp08/html-single/Release_Notes/index.html
Third Party Advisory
securityfocus.com / archive/1/487822/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/507985/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/27706
ExploitPatchThird Party AdvisoryVDB Entry
securityfocus.com / bid/31681
Third Party AdvisoryVDB Entry
vmware.com / security/advisories/VMSA-2008-0010.html
Third Party Advisory
vmware.com / security/advisories/VMSA-2009-0016.html
Third Party Advisory
vupen.com / english/advisories/2008/0488
URL Repurposed
vupen.com / english/advisories/2008/1856/references
URL Repurposed
vupen.com / english/advisories/2008/1981/references
URL Repurposed
vupen.com / english/advisories/2008/2690
URL Repurposed
vupen.com / english/advisories/2008/2780
URL Repurposed
vupen.com / english/advisories/2009/3316
URL Repurposed