Vulnerability record · CVE-2008-2938 · published 13 August 2008
CVE-2008-2938: Apache Tomcat directory traversal allows arbitrary file read
Apache · Tomcat
Apache Tomcat versions 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 contain a directory traversal flaw that lets remote attackers read arbitrary files when allowLinking and UTF-8 are enabled. It is distinct from CVE-2008-2370, and the vendor advisory lists 6.0.16 as the last affected version despite reports that earlier-than-6.0.18 releases were affected.
Description
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.
AV:N/AC:M/Au:N/C:P/I:N/A:N
Automated analysis
high priorityThe flaw allows unauthenticated remote file disclosure and has an extremely high EPSS score, though it requires specific configuration (allowLinking and UTF-8) and is not in KEV.
What it is
Apache Tomcat versions 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 contain a directory traversal flaw that lets remote attackers read arbitrary files when allowLinking and UTF-8 are enabled. It is distinct from CVE-2008-2370, and the vendor advisory lists 6.0.16 as the last affected version despite reports that earlier-than-6.0.18 releases were affected.
Impact
An attacker can read files outside the intended web application directory, exposing configuration, credential, or source files on the server. The CVSS 2.0 vector shows partial confidentiality impact only, with no integrity or availability effect.
Attack surface
Reachable remotely over the network via crafted encoded directory traversal sequences in the URI. No authentication is required per the CVSS vector (Au:N), but the flaw only applies when allowLinking and UTF-8 are enabled, and the access complexity is rated Medium.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.99708 probability, 0.99951 percentile), indicating substantial predicted exploitation activity. Reference tags are advisory and vendor notices only, with no public exploit tag supplied.
What to do
- Upgrade to a Tomcat release after the affected ranges (vendor advisory lists 6.0.16 as last affected; move to a fixed version).
- Disable allowLinking unless it is strictly required.
- Avoid relying on UTF-8 URI handling where the traversal sequences can be decoded, or apply the vendor's recommended configuration changes.
- Apply distribution vendor patches (Red Hat, openSUSE, Mandriva, Apple, Avaya advisories are referenced).
- Restrict network access to Tomcat HTTP connectors to trusted clients where feasible.
Detection
- Inspect web server and Tomcat access logs for encoded traversal sequences (e.g., %2e%2e, %c0%ae, or similar UTF-8 encoded dot patterns) in request URIs.
- Alert on requests containing path traversal patterns targeting files outside the web application root.
- Monitor for unusual file read activity or access to sensitive files by the Tomcat process account.
- Correlate URI patterns with responses returning file contents not normally served by the application.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-2938 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-2938), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.