Moderate severityNVD Advisory· Published Aug 2, 2001· Updated Apr 16, 2026
CVE-2001-0590
CVE-2001-0590
Description
Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tomcat:tomcat-servlet-apiMaven | < 3.2.2 | 3.2.2 |
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- archives.neohapsis.com/archives/bugtraq/2001-04/0031.htmlnvdExploitVendor Advisory
- github.com/advisories/GHSA-x445-mmpw-7r4fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2001-0590ghsaADVISORY
- exchange.xforce.ibmcloud.com/vulnerabilities/6971nvdWEB
- web.archive.org/web/20020711002734/http://archives.neohapsis.com/archives/bugtraq/2001-04/0031.htmlghsaWEB
- www.osvdb.org/5580nvd
- www1.itrc.hp.com/service/cki/docDisplay.donvd
News mentions
0No linked articles in our index yet.