Vulnerability record · CVE-2003-0042 · published 7 February 2003
CVE-2003-0042: Apache Tomcat null-byte URL exposes directory listings and JSP source
Apache · Tomcat
Jakarta Tomcat before 3.3.1a, when running on JDK 1.3.1 or earlier, mishandles URLs containing a null character. This lets a remote attacker bypass index file handling to list directories or retrieve unprocessed JSP source code instead of executing it.
Description
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
medium priorityInformation disclosure only with no integrity or availability impact, but trivially reachable and high EPSS probability on unpatched legacy deployments.
What it is
Jakarta Tomcat before 3.3.1a, when running on JDK 1.3.1 or earlier, mishandles URLs containing a null character. This lets a remote attacker bypass index file handling to list directories or retrieve unprocessed JSP source code instead of executing it.
Impact
An attacker gains read access to directory contents and JSP source code, exposing application logic, credentials, and internal file paths that would normally be hidden or executed server-side.
Attack surface
Reachable over the network via HTTP requests to the Tomcat web server; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, though EPSS shows a high 30-day probability of 0.46 (98.8th percentile).
What to do
- Upgrade Tomcat to 3.3.1a or later, or apply the vendor/Debian DSA-246 patch.
- Upgrade the JDK above 1.3.1, since the flaw depends on that runtime version.
- Restrict network exposure of Tomcat instances that cannot be patched.
- Review web content for sensitive data in JSP source and directory listings.
Detection
- Search HTTP access logs for requests containing encoded or raw null bytes (%00) in the URL path.
- Alert on requests for .jsp files that return source-like content rather than rendered output.
- Monitor for directory listing responses where an index file is expected.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-0042 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0042), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.