Moderate severityNVD Advisory· Published Feb 12, 2008· Updated Jun 16, 2026
CVE-2008-0002
CVE-2008-0002
Description
Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tomcat:tomcatMaven | >= 6.0.0, < 6.0.16 | 6.0.16 |
Affected products
12cpe:2.3:a:apache:tomcat:6.0.10:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:apache:tomcat:6.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.15:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.9:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
36- github.com/advisories/GHSA-5x5f-9r6q-q7mhghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2008-0002ghsaADVISORY
- lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlnvdWEB
- lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.htmlnvdWEB
- marc.infonvdWEB
- security.gentoo.org/glsa/glsa-200804-10.xmlnvdWEB
- support.apple.com/kb/HT3216nvdWEB
- tomcat.apache.org/security-6.htmlnvdWEB
- www.vmware.com/security/advisories/VMSA-2009-0016.htmlnvdWEB
- web.archive.org/web/20080214133036/http://secunia.com/advisories/28915ghsaWEB
- web.archive.org/web/20080715062302/http://secunia.com/advisories/29711ghsaWEB
- web.archive.org/web/20080724052339/http://secunia.com/advisories/28834ghsaWEB
- web.archive.org/web/20081012021650/http://www.securityfocus.com/bid/27703ghsaWEB
- web.archive.org/web/20081013050642/http://secunia.com/advisories/32222ghsaWEB
- web.archive.org/web/20081120062646/http://securityreason.com/securityalert/3638ghsaWEB
- web.archive.org/web/20081121133027/http://www.securityfocus.com/archive/1/487812/100/0/threadedghsaWEB
- web.archive.org/web/20091125140215/http://secunia.com/advisories/37460ghsaWEB
- web.archive.org/web/20120825080137/http://www.securityfocus.com/bid/31681ghsaWEB
- web.archive.org/web/20140723000733/http://secunia.com/advisories/57126ghsaWEB
- web.archive.org/web/20150621204350/http://www.securityfocus.com/archive/1/507985/100/0/threadedghsaWEB
- www.redhat.com/archives/fedora-package-announce/2008-February/msg00315.htmlnvdWEB
- www.redhat.com/archives/fedora-package-announce/2008-February/msg00460.htmlnvdWEB
- secunia.com/advisories/28834nvd
- secunia.com/advisories/28915nvd
- secunia.com/advisories/29711nvd
- secunia.com/advisories/32222nvd
- secunia.com/advisories/37460nvd
- secunia.com/advisories/57126nvd
- securityreason.com/securityalert/3638nvd
- www.securityfocus.com/archive/1/487812/100/0/threadednvd
- www.securityfocus.com/archive/1/507985/100/0/threadednvd
- www.securityfocus.com/bid/27703nvd
- www.securityfocus.com/bid/31681nvd
- www.vupen.com/english/advisories/2008/0488nvd
- www.vupen.com/english/advisories/2008/2780nvd
- www.vupen.com/english/advisories/2009/3316nvd
News mentions
0No linked articles in our index yet.