GHSA-4prh-gqw8-rgh5 · Severity: medium · Ecosystem: maven — Apache Tomcat Directory Traversal
Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.
Conclusion & alert: CVE-2007-0450 is rated High Exploit Risk (70.2/100): CVSS Medium severity, with high exploitation likelihood (EPSS 90.77%, 100th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 29739 | exploit_db | edb | 2007-03-14 | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 90.45% | 90.77% | +0.32% |
| 2 | 2026-05-21 | 89.48% | 90.45% | +0.97% |
| 3 | 2026-04-30 | — | 89.48% | — |
Full EPSS history (26 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
GHSA-4prh-gqw8-rgh5 · Severity: medium · Ecosystem: maven — Apache Tomcat Directory Traversal
| vendor | priority | summary | link |
|---|---|---|---|
gentoo
|
low | CVE-2007-0450: 1 GLSA(s) (200705-03), 1 atom(s) (www-servers/tomcat); latest impact low. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2007-0450 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2007-0450 |
ubuntu
|
medium | CVE-2007-0450 medium priority: Ubuntu including 2 source packages (tomcat5, tomcat5.5), 18 status rows across 9 suites (dapper, edgy, feisty, gutsy, hardy, intrepid, jaunty, karmic, upstream): DNE 7, ignored 5, not-affected 4, needs-triage 2. | https://ubuntu.com/security/CVE-2007-0450 |