Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.

Project Subscriptions

Vendors Products
Http Server Subscribe
Certificate System Subscribe
Enterprise Linux Subscribe
Network Satellite Subscribe
Rhel Application Server Subscribe
Rhel Application Stack Subscribe
Rhel Developer Suite Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4prh-gqw8-rgh5 Apache Tomcat Directory Traversal
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx cve-icon cve-icon
http://docs.info.apple.com/article.html?artnum=306172 cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795 cve-icon cve-icon
http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html cve-icon cve-icon
http://lists.vmware.com/pipermail/security-announce/2008/000003.html cve-icon cve-icon
http://secunia.com/advisories/24732 cve-icon cve-icon
http://secunia.com/advisories/25106 cve-icon cve-icon
http://secunia.com/advisories/25280 cve-icon cve-icon
http://secunia.com/advisories/26235 cve-icon cve-icon
http://secunia.com/advisories/26660 cve-icon cve-icon
http://secunia.com/advisories/27037 cve-icon cve-icon
http://secunia.com/advisories/28365 cve-icon cve-icon
http://secunia.com/advisories/30899 cve-icon cve-icon
http://secunia.com/advisories/30908 cve-icon cve-icon
http://secunia.com/advisories/33668 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200705-03.xml cve-icon cve-icon
http://securityreason.com/securityalert/2446 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm cve-icon cve-icon
http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540 cve-icon cve-icon
http://tomcat.apache.org/security-4.html cve-icon cve-icon
http://tomcat.apache.org/security-5.html cve-icon cve-icon
http://tomcat.apache.org/security-6.html cve-icon cve-icon
http://www.fujitsu.com/global/support/software/security/products-f/interstage-200702e.html cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:241 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_15_sr.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_5_sr.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0327.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0360.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0261.html cve-icon cve-icon
http://www.sec-consult.com/287.html cve-icon cve-icon
http://www.sec-consult.com/fileadmin/Advisories/20070314-0-apache_tomcat_directory_traversal.txt cve-icon cve-icon
http://www.securityfocus.com/archive/1/462791/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/485938/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/500396/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/500412/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/22960 cve-icon cve-icon
http://www.securityfocus.com/bid/25159 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/0975 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2732 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3087 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3386 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/0065 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1979/references cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/0233 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/32988 cve-icon cve-icon
https://lists.apache.org/thread.html/277d42b48b6e9aef50949c0dcc79ce21693091d73da246b3c1981925%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/5b7a23e245c93235c503900da854a143596d901bf1a1f67e851a5de4%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/8d2a579bbd977c225c70cb23b0ec54865fb0dab5da3eff1e060c9935%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r5c616dfc49156e4b06ffab842800c80f4425924d0f20c452c127a53c%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-0450 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10643 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-0450 cve-icon
History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.88844}

epss

{'score': 0.8735}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T12:19:30.290Z

Reserved: 2007-01-23T05:00:00.000Z

Link: CVE-2007-0450

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2007-03-16T22:19:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2007-0450

cve-icon Redhat

Severity : Important

Publid Date: 2007-03-14T00:00:00Z

Links: CVE-2007-0450 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses