{"id":"CVE-2002-2006","description":"The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.","cvssScore":5,"cvssVersion":"2.0","cvssVector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","cvssMetrics":[{"version":"2.0","score":5,"vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"resolved":"MITIGATION-CANDIDATE","published":"2002-12-31","lastModified":"2026-06-16","affectedProducts":[{"vendor":"apache","product":"tomcat","version":"3.0"},{"vendor":"apache","product":"tomcat","version":"3.1"},{"vendor":"apache","product":"tomcat","version":"3.1.1"},{"vendor":"apache","product":"tomcat","version":"3.2"},{"vendor":"apache","product":"tomcat","version":"3.2.1"},{"vendor":"apache","product":"tomcat","version":"3.2.3"},{"vendor":"apache","product":"tomcat","version":"3.2.4"},{"vendor":"apache","product":"tomcat","version":"3.3"},{"vendor":"apache","product":"tomcat","version":"3.3.1"},{"vendor":"apache","product":"tomcat","version":"4.0.0"},{"vendor":"apache","product":"tomcat","version":"4.0.1"},{"vendor":"apache","product":"tomcat","version":"4.0.2"},{"vendor":"apache","product":"tomcat","version":"4.0.3"},{"vendor":"apache","product":"tomcat","version":"4.1.0"}],"totalAffectedProducts":1,"references":[{"url":"https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5@\u003cdev.tomcat.apache.org\u003e","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74@\u003cdev.tomcat.apache.org\u003e","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3@\u003cdev.tomcat.apache.org\u003e","source":"osv","tags":["WEB"]},{"url":"https://web.archive.org/web/20020602051837/http://archives.neohapsis.com/archives/bugtraq/2002-04/0311.html","source":"osv","tags":["WEB"]},{"url":"https://web.archive.org/web/20021026082659/http://online.securityfocus.com/bid/4575","source":"osv","tags":["WEB"]},{"url":"https://web.archive.org/web/20030104173336/http://www.iss.net/security_center/static/8932.php","source":"osv","tags":["WEB"]},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1","source":"osv","tags":["WEB"]},{"url":"http://tomcat.apache.org/security-4.html","source":"osv","tags":["WEB"]},{"url":"http://archives.neohapsis.com/archives/bugtraq/2002-04/0311.html","source":"cve@mitre.org","tags":["Exploit"]},{"url":"http://secunia.com/advisories/30899","source":"cve@mitre.org"}],"reasoning":{"decidingSource":"open-source-maven","decidingReason":"This CVE affects an open-source Java library published on Maven Central (Maven packages: org.apache.tomcat:tomcat), so it is squarely in ARMR's territory and the source needed to understand the defect is public. That makes it a candidate for an ARMR patch rule. No rule exists and none is scheduled: the diff between the affected and fixed versions has not been read, and a closer look may find no hook point ARMR can act on.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.apache.tomcat:tomcat"},{"rule":"patch-hint","stage":"disposition","outcome":"no-match"},{"rule":"open-source-maven","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"Open-source Maven artifact indexed by OSV (Maven packages: org.apache.tomcat:tomcat). The source is public, which makes an ARMR patch rule a candidate; nothing here establishes that one can be written.","decisive":true},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"no-match"},{"rule":"below-action-threshold","stage":"disposition","outcome":"withheld","detail":"Has 1 known POC(s) clearing the evidence bar — requires review despite MEDIUM severity"},{"rule":"no-exploit-published","stage":"disposition","outcome":"no-match","detail":"A KEV listing, a CISA verdict of active exploitation, or a reviewed exploit catalogue carries this CVE — somebody has published a working exploit, so it stays a candidate"}],"affectedProducts":[{"vendor":"apache","product":"tomcat","isKnown":true,"cpe":"cpe:2.3:a:apache:tomcat:3.0:*:*:*:*:*:*:*","source":"yaml"}],"affectedPackages":[{"name":"org.apache.tomcat:tomcat","introduced":"4.0.0","fixed":"4.1.0"},{"name":"org.apache.tomcat:tomcat","introduced":"3.0","fixed":"3.3a"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"unverified","type":"patch-rule"},"review":{"state":"automated","basis":"inferred"}},"exploits":[{"source":"exploit-db","url":"https://www.exploit-db.com/exploits/21412","title":"Apache Tomcat 4.0/4.1 - Servlet Full Path Disclosure","date":"2002-04-23"}],"signals":{"hasPOC":true,"pocCount":1,"pocSources":["exploit-db"],"firstPOCDate":"2002-04-23"},"kev":{"inKEV":false},"epss":{"available":true,"score":0.30673,"percentile":0.98141},"ssvc":{"available":false}}