Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.
| Software | From | Fixed in |
|---|---|---|
| apache / tomcat | 4.0.4 | 4.0.4.x |
| apache / tomcat | 4.1.9-beta | 4.1.9-beta.x |
| apache / tomcat | 4.0.3 | 4.0.3.x |
| apache / tomcat | 4.0.1 | 4.0.1.x |
| apache / tomcat | 4.1.3-beta | 4.1.3-beta.x |
| apache / tomcat | 4.1.10 | 4.1.10.x |
| apache / tomcat | 4.1.0 | 4.1.0.x |
| apache / tomcat | 4.0.2 | 4.0.2.x |
| apache / tomcat | 4.0.5 | 4.0.5.x |
| apache / tomcat | 4.0.0 | 4.0.0.x |