CVE-2000-0672
The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attacker
The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory.
MEDIUM · CVSS 5
EPSS 0.03158
Schedule remediation
- Public exploit or PoC is available
Sigma rules1
YARA rules0