{"id":"CVE-2002-1394","description":"Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.","cvssScore":7.5,"cvssVersion":"2.0","cvssVector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","cvssMetrics":[{"version":"2.0","score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-200"],"resolved":"NO-EXPLOIT-PUBLISHED","published":"2003-01-17","lastModified":"2026-06-16","affectedProducts":[{"vendor":"apache","product":"tomcat","version":"4.0.0"},{"vendor":"apache","product":"tomcat","version":"4.0.1"},{"vendor":"apache","product":"tomcat","version":"4.0.2"},{"vendor":"apache","product":"tomcat","version":"4.0.3"},{"vendor":"apache","product":"tomcat","version":"4.0.4"},{"vendor":"apache","product":"tomcat","version":"4.0.5"},{"vendor":"apache","product":"tomcat","version":"4.1.0"},{"vendor":"apache","product":"tomcat","version":"4.1.3","update":"beta"},{"vendor":"apache","product":"tomcat","version":"4.1.9","update":"beta"},{"vendor":"apache","product":"tomcat","version":"4.1.10"}],"totalAffectedProducts":1,"references":[{"url":"https://archive.apache.org/dist/tomcat/tomcat-4/archive/v4.0.6/README.html","source":"osv","tags":["WEB"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/10376","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5@\u003cdev.tomcat.apache.org\u003e","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3@\u003cdev.tomcat.apache.org\u003e","source":"osv","tags":["WEB"]},{"url":"https://web.archive.org/web/20030412075128/http://rhn.redhat.com/errata/RHSA-2003-075.html","source":"osv","tags":["WEB"]},{"url":"https://web.archive.org/web/20030705143220/http://www.securityfocus.com/bid/6562","source":"osv","tags":["WEB"]},{"url":"https://web.archive.org/web/20041024213235/http://rhn.redhat.com/errata/RHSA-2003-082.html","source":"osv","tags":["WEB"]},{"url":"https://web.archive.org/web/20070430073829/http://www.debian.org/security/2003/dsa-225","source":"osv","tags":["WEB"]},{"url":"http://issues.apache.org/bugzilla/show_bug.cgi?id=13365","source":"osv","tags":["WEB"]},{"url":"http://marc.info/?l=bugtraq\u0026m=103470282514938\u0026w=2","source":"osv","tags":["WEB"]}],"reasoning":{"decidingSource":"no-exploit-published","decidingReason":"This CVE is not listed in CISA KEV, CISA Vulnrichment records no active exploitation, and no reviewed exploit catalogue carries an entry for it. Nobody has published something a stranger can run, so it is not a candidate for a rule ahead of the ones where somebody has; an upstream fix path does exist, so the remediation half of the candidacy still holds. This is a statement about what has been published, not about whether the defect is reachable or serious.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.apache.tomcat:tomcat"},{"rule":"patch-hint","stage":"disposition","outcome":"no-match"},{"rule":"open-source-maven","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"Open-source Maven artifact indexed by OSV (Maven packages: org.apache.tomcat:tomcat). The source is public, which makes an ARMR patch rule a candidate; nothing here establishes that one can be written."},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"no-match"},{"rule":"below-action-threshold","stage":"disposition","outcome":"no-match","detail":"Severity is HIGH — only MEDIUM/LOW are deprioritized"},{"rule":"no-exploit-published","stage":"disposition","outcome":"matched","status":"NO-EXPLOIT-PUBLISHED","detail":"No working exploit has been published, and an upstream fix path does exist, so the remediation half of the candidacy still holds.","decisive":true}],"affectedProducts":[{"vendor":"apache","product":"tomcat","isKnown":true,"cpe":"cpe:2.3:a:apache:tomcat:4.0.0:*:*:*:*:*:*:*","source":"yaml"}],"affectedPackages":[{"name":"org.apache.tomcat:tomcat","introduced":"0","fixed":"4.0.6"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"unverified","type":"patch-rule"},"review":{"state":"automated","basis":"upstream-data"}},"signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.05855,"percentile":0.9278},"ssvc":{"available":false}}