Loading...
Loading...
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.
August 13, 2008
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2008-2938
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.