FlawAtlas
Search the atlas
CVE-2015-5345 Moderate

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a directory via a URL that lacks a trailing / (slash) character.

Exploit probability 18.4%
Published May 14, 2022
Required by Not available
Last source change August 28, 2025

02 / AFFECTED SOFTWARE

Affected packages

Maven org.apache.tomcat:tomcat

46 explicit affected versions

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-rh8q-vjgf-gf74

The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a directory via a URL that lacks a trailing / (slash) character.

View original source

05 / REFERENCES

Further evidence