CVE-2015-5174: Apache Tomcat

Medium severity, CVSS 4.3. EPSS: 12.6% chance of exploitation in the next 30 days.

Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application in a getResource, getResourceAsStream, or getResourcePaths call, as demonstrated by the $CATALINA_BASE/webapps directory.

Affected products

  • Apache Tomcat: version 6.0.0 only; version 6.0.1 only; version 6.0.2 only; version 6.0.4 only; version 6.0.10 only; version 6.0.11 only; …
  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
  • Debian Debian Linux: version 7.0 only; version 8.0 only

Published 2016-02-25. Last modified 2026-06-17.