CVE-2002-2006

CVSS 5.0 - MEDIUM
Description

The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.

Affected Products
14
Vendor Product Version
apache tomcat 3.0
apache tomcat 3.1
apache tomcat 3.1.1
apache tomcat 3.2
apache tomcat 3.2.1
apache tomcat 3.2.3
apache tomcat 3.2.4
apache tomcat 3.3
apache tomcat 3.3.1
apache tomcat 4.0.0
apache tomcat 4.0.1
apache tomcat 4.0.2
apache tomcat 4.0.3
apache tomcat 4.1.0
Weakness Types
NVD-CWE-Other
CVE Information
CVE ID:
CVE-2002-2006
Published:
2002-12-31
Modified:
2026-04-16
CVSS Score:
5.0
Severity:
MEDIUM
Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
Affected Vendors
apache
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL