Medium severity4.2NVD Advisory· Published Jun 5, 2009· Updated Jun 16, 2026
CVE-2009-0783
CVE-2009-0783
Description
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tomcat:tomcatMaven | >= 4.1.0, <= 4.1.39 | — |
org.apache.tomcat:tomcatMaven | >= 5.5.0, <= 5.5.27 | — |
org.apache.tomcat:tomcatMaven | >= 6.0.0, < 6.0.20 | 6.0.20 |
Affected products
2Patches
Vulnerability mechanics
References
56- svn.apache.org/viewvcnvdPatchWEB
- svn.apache.org/viewvcnvdPatchWEB
- svn.apache.org/viewvcnvdPatchWEB
- svn.apache.org/viewvcnvdPatchWEB
- svn.apache.org/viewvcnvdPatchWEB
- tomcat.apache.org/security-4.htmlnvdPatchVendor AdvisoryWEB
- tomcat.apache.org/security-5.htmlnvdPatchVendor AdvisoryWEB
- tomcat.apache.org/security-6.htmlnvdPatchVendor AdvisoryWEB
- issues.apache.org/bugzilla/show_bug.cginvdIssue TrackingPatchWEB
- lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlnvdThird Party AdvisoryWEB
- marc.infonvdThird Party AdvisoryWEB
- marc.infonvdThird Party AdvisoryWEB
- marc.infonvdThird Party AdvisoryWEB
- secunia.com/advisories/35685nvdVendor AdvisoryWEB
- secunia.com/advisories/35788nvdVendor AdvisoryWEB
- secunia.com/advisories/37460nvdVendor AdvisoryWEB
- secunia.com/advisories/42368nvdVendor AdvisoryWEB
- sunsolve.sun.com/search/document.donvdThird Party AdvisoryWEB
- support.apple.com/kb/HT4077nvdThird Party AdvisoryWEB
- www.debian.org/security/2011/dsa-2207nvdThird Party AdvisoryWEB
- www.mandriva.com/security/advisoriesnvdThird Party AdvisoryWEB
- www.mandriva.com/security/advisoriesnvdThird Party AdvisoryWEB
- www.mandriva.com/security/advisoriesnvdThird Party AdvisoryWEB
- www.securityfocus.com/archive/1/504090/100/0/threadednvdThird Party AdvisoryVDB EntryWEB
- www.securityfocus.com/archive/1/507985/100/0/threadednvdThird Party AdvisoryVDB EntryWEB
- www.securityfocus.com/bid/35416nvdThird Party AdvisoryVDB EntryWEB
- www.securitytracker.com/idnvdThird Party AdvisoryVDB EntryWEB
- www.vmware.com/security/advisories/VMSA-2009-0016.htmlnvdThird Party AdvisoryWEB
- www.vupen.com/english/advisories/2009/1856nvdVendor AdvisoryWEB
- www.vupen.com/english/advisories/2009/3316nvdVendor AdvisoryWEB
- www.vupen.com/english/advisories/2010/3056nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-hhjg-g8xq-hhr3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2009-0783ghsaADVISORY
- www.redhat.com/archives/fedora-package-announce/2009-November/msg01156.htmlnvdThird Party AdvisoryWEB
- www.redhat.com/archives/fedora-package-announce/2009-November/msg01216.htmlnvdThird Party AdvisoryWEB
- www.redhat.com/archives/fedora-package-announce/2009-November/msg01246.htmlnvdThird Party AdvisoryWEB
- lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlnvdMailing ListWEB
- exchange.xforce.ibmcloud.com/vulnerabilities/51195nvdVDB EntryWEB
- issues.apache.org/bugzilla/show_bug.cginvdIssue TrackingWEB
- lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3EnvdWEB
- lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e@%3Cdev.tomcat.apache.org%3EghsaWEB
- lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3EnvdWEB
- lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5@%3Cdev.tomcat.apache.org%3EghsaWEB
- lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3EnvdWEB
- lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa@%3Cdev.tomcat.apache.org%3EghsaWEB
- lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3EnvdWEB
- lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74@%3Cdev.tomcat.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3EnvdWEB
- lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf@%3Cdev.tomcat.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3EnvdWEB
- lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5@%3Cdev.tomcat.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3EnvdWEB
- lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3@%3Cdev.tomcat.apache.org%3EghsaWEB
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10716nvdTool SignatureWEB
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18913nvdTool SignatureWEB
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6450nvdTool SignatureWEB
News mentions
0No linked articles in our index yet.