Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-5461

38
FAUCET Score

CVE-2007-5461 describes an absolute path traversal vulnerability affecting Apache Tomcat versions 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14 under specific configurations. This flaw allows remote authenticated users to read arbitrary files by crafting a WebDAV write request with a SYSTEM tag in an entity. The vulnerability has a CVSS score of 3.5, indicating a medium attack complexity and requiring authentication, with the potential impact limited to partial confidentiality. While not listed in CISA's KEV catalog, public exploit code exists on ExploitDB, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
4.0.0CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:4.0.0:*:*:*:*:*:*:*
4.0.1CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:4.0.1:*:*:*:*:*:*:*
4.0.2CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:4.0.2:*:*:*:*:*:*:*
4.0.3CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:4.0.3:*:*:*:*:*:*:*
4.0.4CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:4.0.4:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

3.5LOW

AV:N/AC:M/Au:S/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
SINGLE
Exploitability Score
6.8
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
39.68%
Probability of exploitation in next 30 days
EPSS Percentile
98.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-4552 · Oct 21, 2007
This CVE's current EPSS score of 0.3968 is in the 100th percentile among its peer group of 1,637 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (111)

redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: glassfish-javamail-0:1.4.0-0jpp.ep1.8
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: hibernate3-1:3.2.4-1.SP1_CP02.0jpp.ep1.1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: hibernate3-annotations-0:3.2.1-1.patch02.1jpp.ep1.2.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: hibernate3-entitymanager-0:3.2.1-1jpp.ep1.6.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: hsqldb-1:1.8.0.8-2.patch01.1jpp.ep1.1
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jacorb-0:2.3.0-1jpp.ep1.4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jboss-aop-0:1.5.5-1.CP01.0jpp.ep1.1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jbossas-0:4.2.0-3.GA_CP02.ep1.3.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jboss-cache-0:1.4.1-4.SP8_CP01.1jpp.ep1.1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jboss-remoting-0:2.2.2-3.SP4.0jpp.ep1.1
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jboss-seam-0:1.2.1-1.ep1.3.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jbossweb-0:2.0.0-3.CP05.0jpp.ep1.1
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jbossws-jboss42-0:1.2.1-0jpp.ep1.2.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jcommon-0:1.0.12-1jpp.ep1.2.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jfreechart-0:1.0.9-1jpp.ep1.2.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jgroups-1:2.4.1-1.SP4.0jpp.ep1.2
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: rh-eap-docs-0:4.2.0-3.GA_CP02.ep1.1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: hibernate3-0:3.2.4-1.SP1_CP02.0jpp.ep1.1.el5.1
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: hibernate3-annotations-0:3.2.1-1.patch02.1jpp.ep1.2.el5.1
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jacorb-0:2.3.0-1jpp.ep1.5.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jboss-aop-0:1.5.5-1.CP01.0jpp.ep1.1.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jbossas-0:4.2.0-4.GA_CP02.ep1.3.el5.3
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jboss-cache-0:1.4.1-4.SP8_CP01.1jpp.ep1.1.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jboss-remoting-0:2.2.2-3.SP4.0jpp.ep1.1.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jboss-seam-0:1.2.1-1.ep1.3.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jbossweb-0:2.0.0-3.CP05.0jpp.ep1.1.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jcommon-0:1.0.12-1jpp.ep1.2.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jfreechart-0:1.0.9-1jpp.ep1.2.el5.1
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: rh-eap-docs-0:4.2.0-3.GA_CP02.ep1.1.el5.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: ant-0:1.6.5-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: avalon-logkit-0:1.2-2jpp_4rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: axis-0:1.2.1-1jpp_3rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: classpathx-jaf-0:1.0-2jpp_6rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: classpathx-mail-0:1.1.1-2jpp_8rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: geronimo-specs-0:1.0-0.M4.1jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: jakarta-commons-modeler-0:2.0-3jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: log4j-0:1.2.12-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: mx4j-1:3.0.1-1jpp_4rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: pcsc-lite-0:1.3.3-3.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-ca-0:7.3.0-20.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-java-tools-0:7.3.0-10.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-kra-0:7.3.0-14.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-manage-0:7.3.0-19.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-native-tools-0:7.3.0-6.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-ocsp-0:7.3.0-13.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-tks-0:7.3.0-13.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: tomcat5-0:5.5.23-0jpp_4rh.16
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: xerces-j2-0:2.7.1-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: xml-commons-0:1.3.02-2jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Developer Suite V.3Fixed in: tomcat5-0:5.5.23-0jpp_11rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: tomcat5-0:5.5.23-0jpp.3.0.3.el5_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: jabberd-0:2.0s10-3.38.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: openmotif21-0:2.1.30-11.RHEL4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: perl-Crypt-CBC-0:2.24-1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-modjk-0:1.2.23-2rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-modperl-0:1.29-16.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-modssl-0:2.8.12-8.rhn.10.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: jabberd-0:2.0s10-3.37.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: openmotif21-0:2.1.30-9.RHEL3.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: perl-Crypt-CBC-0:2.24-1.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-modjk-0:1.2.23-2rhn.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-modperl-0:1.29-16.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-modssl-0:2.8.12-8.rhn.10.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: jabberd-0:2.0s10-3.38.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: openmotif21-0:2.1.30-11.RHEL4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: perl-Crypt-CBC-0:2.24-1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-modjk-0:1.2.23-2rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-modperl-0:1.29-16.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-modssl-0:2.8.12-8.rhn.10.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.1Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.1Fixed in: mod_perl-0:2.0.2-12.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.1Fixed in: perl-Crypt-CBC-0:2.24-1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.1Fixed in: rhn-web-0:5.1.1-7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.1Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: concurrent-0:1.3.4-7jpp.ep1.6.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: glassfish-jaf-0:1.1.0-0jpp.ep1.10.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: glassfish-javamail-0:1.4.0-0jpp.ep1.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: glassfish-jsf-0:1.2_04-1.p02.0jpp.ep1.18
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: glassfish-jstl-0:1.2.0-0jpp.ep1.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: hibernate3-1:3.2.4-1.SP1_CP02.0jpp.ep1.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: hibernate3-annotations-0:3.2.1-1.patch02.1jpp.ep1.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: hibernate3-entitymanager-0:3.2.1-1jpp.ep1.6.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: hsqldb-1:1.8.0.8-2.patch01.1jpp.ep1.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: jacorb-0:2.3.0-1jpp.ep1.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: jboss-aop-0:1.5.5-1.CP01.0jpp.ep1.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: jbossas-0:4.2.0-3.GA_CP02.ep1.3.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: jboss-cache-0:1.4.1-4.SP8_CP01.1jpp.ep1.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: jboss-common-0:1.2.1-0jpp.ep1.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: jboss-remoting-0:2.2.2-3.SP4.0jpp.ep1.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: jboss-seam-0:1.2.1-1.ep1.3.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: jbossweb-0:2.0.0-3.CP05.0jpp.ep1.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: jbossws-wsconsume-impl-0:2.0.0-0jpp.ep1.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: jbossxb-0:1.0.0-2.SP1.0jpp.ep1.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: jcommon-0:1.0.12-1jpp.ep1.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: jfreechart-0:1.0.9-1jpp.ep1.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: jgroups-1:2.4.1-1.SP4.0jpp.ep1.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: rh-eap-docs-0:4.2.0-3.GA_CP02.ep1.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: wsdl4j-0:1.6.2-1jpp.ep1.8
View patch
redhatpatch availablevia redhat_api
Product: RHAPS Version 2 for RHEL 4Fixed in: tomcat5-0:5.5.23-0jpp_4rh.9
View patch

Vendor Advisories (2)

mavenGHSA-v5p2-vg3c-pmrrlow

Apache Tomcat Path Traversal Vulnerability

May 1, 2022
redhatCVE-2007-5461Important

Absolute path traversal Apache Tomcat WEBDAV

Oct 14, 2007

References

geronimo.apache.org / 2007/10/18/potential-vulnerability-in-apache-tomcat-webdav-servlet.html
issues.apache.org / jira/browse/GERONIMO-3549
lists.apple.com / archives/security-announce/2008//Jun/msg00002.html
lists.apple.com / archives/security-announce/2008/Oct/msg00001.html
lists.opensuse.org / opensuse-security-announce/2008-03/msg00001.html
lists.opensuse.org / opensuse-security-announce/2009-02/msg00002.html
mail-archives.apache.org / mod_mbox/tomcat-users/200710.mbox/%3C47135C2D.1000705%40apache.org%3E
marc.info
marc.info
Exploit
rhn.redhat.com / errata/RHSA-2008-0630.html
secunia.com / advisories/27398
secunia.com / advisories/27446
secunia.com / advisories/27481
secunia.com / advisories/27727
secunia.com / advisories/28317
secunia.com / advisories/28361
secunia.com / advisories/29242
secunia.com / advisories/29313
secunia.com / advisories/29711
secunia.com / advisories/30676
secunia.com / advisories/30802
secunia.com / advisories/30899
secunia.com / advisories/30908
secunia.com / advisories/31493
secunia.com / advisories/32120
secunia.com / advisories/32222
secunia.com / advisories/32266
secunia.com / advisories/37460
secunia.com / advisories/57126
security.gentoo.org / glsa/glsa-200804-10.xml
exchange.xforce.ibmcloud.com / vulnerabilities/37243
lists.apache.org / thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9202
sunsolve.sun.com / search/document.do
support.apple.com / kb/HT2163
support.apple.com / kb/HT3216
support.avaya.com / elmodocs2/security/ASA-2008-401.htm
exploit-db.com / exploits/4530
redhat.com / archives/fedora-package-announce/2007-November/msg00525.html
tomcat.apache.org / security-4.html
tomcat.apache.org / security-5.html
tomcat.apache.org / security-6.html
www-1.ibm.com / support/docview.wss
debian.org / security/2008/dsa-1447
debian.org / security/2008/dsa-1453
mandriva.com / security/advisories
mandriva.com / security/advisories
redhat.com / support/errata/RHSA-2008-0042.html
redhat.com / support/errata/RHSA-2008-0195.html
redhat.com / support/errata/RHSA-2008-0261.html
redhat.com / support/errata/RHSA-2008-0862.html
securityfocus.com / archive/1/507985/100/0/threaded
securityfocus.com / bid/26070
securityfocus.com / bid/31681
securitytracker.com / id
vmware.com / security/advisories/VMSA-2008-0010.html
vmware.com / security/advisories/VMSA-2009-0016.html
vupen.com / english/advisories/2007/3622
vupen.com / english/advisories/2007/3671
vupen.com / english/advisories/2007/3674
vupen.com / english/advisories/2008/1856/references
vupen.com / english/advisories/2008/1979/references
vupen.com / english/advisories/2008/1981/references
vupen.com / english/advisories/2008/2780
vupen.com / english/advisories/2008/2823
vupen.com / english/advisories/2009/3316