VDB
RHSA-2003%3A075
RHSA-2003%3A075
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Stronghold 4 for Red Hat Enterprise Linux |
Timeline
- Apr 9, 2003 CVE Published
- Nov 21, 2025 CVE Updated
- Aug 7, 2026 Distribution Patch
- Aug 7, 2026 Distribution Patch
- Aug 7, 2026 Security Advisory
- Aug 7, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2003:075 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2003/rhsa-2003_075.json advisory
- https://access.redhat.com/security/cve/CVE-2002-1394 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1616907 issue
- https://www.cve.org/CVERecord?id=CVE-2002-1394 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2002-1394 advisory