{"id":"CVE-2002-1987","description":"Directory traversal vulnerability in view_source.jsp in Resin 2.1.2 allows remote attackers to read arbitrary files via a \"\\..\" (backslash dot dot).","cvssScore":5,"cvssVersion":"2.0","cvssVector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","cvssMetrics":[{"version":"2.0","score":5,"vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"resolved":"MITIGATED-BY-RASP","published":"2002-12-31","lastModified":"2026-06-16","affectedProducts":[{"vendor":"caucho technology","product":"resin","version":"2.1.2"}],"totalAffectedProducts":1,"references":[{"url":"http://online.securityfocus.com/archive/1/277225","source":"cve@mitre.org"},{"url":"http://www.iss.net/security_center/static/9351.php","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/5031","source":"cve@mitre.org"}],"reasoning":{"decidingSource":"h2-history","decidingReason":"Manual classification assigned status: MITIGATED-BY-SECURE-RULE","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"matched","status":"MITIGATED-BY-RASP","detail":"Found in legacy manual classifications","decisive":true}]},"assessment":{"record":{"state":"active"},"protection":{"level":"full","mechanisms":["security-rule"]},"action":{"state":"available","type":"security-rule"},"review":{"state":"human","basis":"manual-review"}},"h2Comments":"## Manual Classification Context\n\n\n**Products:** RESIN SERVLET/JSP CONTAINER","signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.02548,"percentile":0.84132},"ssvc":{"available":false}}