Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-1232

65
FAUCET Score

CVE-2008-1232 describes a Cross-Site Scripting (XSS) vulnerability in Apache Tomcat versions 4.1.0-4.1.37, 5.5.0-5.5.26, and 6.0.0-6.0.16. This flaw allows remote attackers to inject arbitrary web script or HTML by crafting a malicious string passed to the HttpServletResponse.sendError method. With a CVSS score of 4.3 (medium), this vulnerability has a network attack vector and medium attack complexity, potentially leading to information disclosure or defacement. While not listed in CISA's KEV catalog, an exploit is publicly available on ExploitDB, though there is no evidence of active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.1.0, <= 4.1.37CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
>= 5.5.0, <= 5.5.26CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
>= 6.0.0, <= 6.0.16CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
75.87%
Probability of exploitation in next 30 days
EPSS Percentile
99.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-32138 · Aug 1, 2008
This CVE's current EPSS score of 0.7587 is in the 100th percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (32)

mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcatFixed in: 4.1.38
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcatFixed in: 5.5.27
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcatFixed in: 6.0.17
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: ant-0:1.6.5-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: avalon-logkit-0:1.2-2jpp_4rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: axis-0:1.2.1-1jpp_3rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: classpathx-jaf-0:1.0-2jpp_6rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: classpathx-mail-0:1.1.1-2jpp_8rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: geronimo-specs-0:1.0-0.M4.1jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: jakarta-commons-modeler-0:2.0-3jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: log4j-0:1.2.12-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: mx4j-1:3.0.1-1jpp_4rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: pcsc-lite-0:1.3.3-3.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-ca-0:7.3.0-20.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-java-tools-0:7.3.0-10.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-kra-0:7.3.0-14.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-manage-0:7.3.0-19.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-native-tools-0:7.3.0-6.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-ocsp-0:7.3.0-13.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-tks-0:7.3.0-13.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: tomcat5-0:5.5.23-0jpp_4rh.16
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: xerces-j2-0:2.7.1-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: xml-commons-0:1.3.02-2jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Developer Suite V.3Fixed in: tomcat5-0:5.5.23-0jpp_12rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: tomcat5-0:5.5.23-0jpp.7.el5_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: jbossweb-0:2.0.0-5.CP07.0jpp.ep1.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: tomcat5-0:5.0.30-0jpp_12rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.1Fixed in: tomcat5-0:5.0.30-0jpp_12rh
View patch
redhatpatch availablevia redhat_api
Product: RHAPS Version 2 for RHEL 4Fixed in: tomcat5-0:5.5.23-0jpp_4rh.9
View patch

Vendor Advisories (2)

mavenGHSA-q74x-qqhr-f8rxmedium

Apache Tomcat Cross-site scripting (XSS) vulnerability

May 1, 2022
redhatCVE-2008-1232Low

tomcat: Cross-Site-Scripting enabled by sendError call

Aug 1, 2008

References

community.ca.com / blogs/casecurityresponseblog/archive/2009/06/15/ca20090615-02-ca-service-desk-tomcat-cross-site-scripting-vulnerability.aspx
Broken Link
lists.apple.com / archives/security-announce/2008/Oct/msg00001.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2008-09/msg00004.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2009-02/msg00002.html
Third Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
secunia.com / advisories/31379
Broken Link
secunia.com / advisories/31381
Broken Link
secunia.com / advisories/31639
Broken Link
secunia.com / advisories/31865
Broken Link
secunia.com / advisories/31891
Broken Link
secunia.com / advisories/31982
Broken Link
secunia.com / advisories/32120
Broken Link
secunia.com / advisories/32222
Broken Link
secunia.com / advisories/32266
Broken Link
secunia.com / advisories/33797
Broken Link
secunia.com / advisories/33999
Broken Link
secunia.com / advisories/34013
Broken Link
secunia.com / advisories/35474
Broken Link
secunia.com / advisories/36108
Broken Link
secunia.com / advisories/37460
Broken Link
secunia.com / advisories/57126
Broken Link
securityreason.com / securityalert/4098
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/44155
Third Party AdvisoryVDB Entry
lists.apache.org / thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11181
Tool Signature
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5985
Tool Signature
support.ca.com / irj/portal/anonymous/phpsupcontent
Broken Link
support.ca.com / irj/portal/anonymous/phpsupcontent
Broken Link
support.apple.com / kb/HT3216
Third Party Advisory
support.avaya.com / elmodocs2/security/ASA-2008-401.htm
Third Party Advisory
redhat.com / archives/fedora-package-announce/2008-September/msg00712.html
Third Party Advisory
redhat.com / archives/fedora-package-announce/2008-September/msg00859.html
Third Party Advisory
redhat.com / archives/fedora-package-announce/2008-September/msg00889.html
Third Party Advisory
tomcat.apache.org / security-4.html
Vendor Advisory
tomcat.apache.org / security-5.html
Vendor Advisory
tomcat.apache.org / security-6.html
Vendor Advisory
mandriva.com / security/advisories
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0648.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0862.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0864.html
Third Party Advisory
securityfocus.com / archive/1/495021/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/504351/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/505556/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/507985/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/30496
ExploitPatchThird Party AdvisoryVDB Entry
securityfocus.com / bid/31681
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
vmware.com / security/advisories/VMSA-2009-0002.html
Third Party Advisory
vmware.com / security/advisories/VMSA-2009-0016.html
Third Party Advisory
vupen.com / english/advisories/2008/2305
URL Repurposed
vupen.com / english/advisories/2008/2780
URL Repurposed
vupen.com / english/advisories/2008/2823
URL Repurposed
vupen.com / english/advisories/2009/0320
URL Repurposed
vupen.com / english/advisories/2009/0503
URL Repurposed
vupen.com / english/advisories/2009/1609
URL Repurposed
vupen.com / english/advisories/2009/2194
URL Repurposed
vupen.com / english/advisories/2009/3316
URL Repurposed