← Vulnerability feed

Vulnerability record · CVE-2008-5518 · published 17 April 2009

CVE-2008-5518: Apache geronimo path traversal vulnerability

Apache · Geronimo

Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group, (2) artifact, (3) version, or (4) fileType parameter to console/portal//Services/Repository (aka the Services/Repository portlet); the (5) createDB parameter to console/portal/Embedded DB/DB Manager (aka the Embedded DB/DB Manager portlet); or the (6) filename parameter to the createKeystore script in the Security/Keystores portlet.

9.4 CVSS 2.0 High EPSS 36% · top 1.6% CWE-22 · Path traversal
9.4CVSS 2.0 base score
36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
22References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group, (2) artifact, (3) version, or (4) fileType parameter to console/portal//Services/Repository (aka the Services/Repository portlet); the (5) createDB parameter to console/portal/Embedded DB/DB Manager (aka the Embedded DB/DB Manager portlet); or the (6) filename parameter to the createKeystore script in the Security/Keystores portlet.

AV:N/AC:L/Au:N/C:C/I:C/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-5518 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-1777Apache geronimo code injection vulnerabilityThe JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and o…EPSS 9.8%10.0CVE-2007-4548Apache geronimo improper authentication vulnerabilityThe login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote att…EPSS 4.2%7.8CVE-2011-5034Apache Geronimo predictable hash collision denial of serviceApache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably. A …EPSS 81%analysed7.5CVE-2007-5797Apache geronimo improper authentication vulnerabilitySQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass aut…EPSS 3.1%6.8CVE-2009-0039Apache geronimo cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 …EPSS 11%5.0CVE-2007-5085Apache geronimo improper authentication vulnerabilityUnspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "a…EPSS 3.2%4.3CVE-2009-0038Apache geronimo cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow r…EPSS 18%4.3CVE-2006-0254Apache geronimo vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) …EPSS 32%

Source: NIST National Vulnerability Database (record CVE-2008-5518), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.