Apache Tomcat’s security documentation continues to catalogue numerous historical vulnerabilities in the end-of-life 4.0.x and 4.1.x branches, including information disclosure, denial of service, cross-site scripting, session hijacking, directory traversal, access-control bypass, and a Security Manager bypass. The flaws can expose JSP source, WEB-INF resources, prior-request data, session identifiers, and arbitrary files, or enable request-thread exhaustion and proxy-context bypasses.
Apache will issue no further security fixes for Tomcat 4.x; some listed defects, including CVE-2005-4836, were explicitly not fixed in 4.1.x. The project notes that CVE-2008-2938 stemmed from JVM UTF-8 URL-decoding behavior, with Tomcat 4.1.39 adding a workaround, and advises organizations still operating Tomcat 4.x to migrate to a supported release—currently Tomcat 9.0.x or later—to receive security updates.

Map this exposure pattern across your cloud, code, and identities.
25 events from the most recent confirmed update back to the earliest known activity.
The Apache Tomcat Project committed a reformatted version of its Tomcat 4.x security-vulnerabilities page. The commit documented historical issues and did not announce a new vulnerability or security fix.
CVE-2009-0783 could allow a rogue web application to replace Tomcat's XML parser and view or alter other deployed applications' web.xml or TLD files. It was fixed in Tomcat 4.1.40.
CVE-2009-0781 was an XSS vulnerability in the calendar application included in Tomcat's examples web application. It was fixed in Tomcat 4.1.40.
CVE-2009-0580 enabled username enumeration through illegally URL-encoded passwords when FORM authentication used MemoryRealm; early JDBCRealm and DataSourceRealm versions were also affected. It was fixed in Tomcat 4.1.40.
CVE-2009-0033 allowed invalid headers sent through the Java AJP connector to put a mod_jk load-balancing worker into an error state, causing denial of service. It was fixed in Tomcat 4.1.40.
CVE-2008-5515 allowed crafted request parameters used with RequestDispatcher to reach security-constrained or WEB-INF content in Tomcat 4.1.0 through 4.1.39. It was fixed in Tomcat 4.1.40.
CVE-2008-4308 could disclose POST data from a previous request under specific error-processing conditions in Tomcat 4.1.32 through 4.1.34.
CVE-2008-3271 could, in rare thread-processing conditions, allow a non-permitted IP address to access a context protected by a RequestFilterValve-derived valve, including RemoteAddrValve and RemoteHostValve.
CVE-2008-2938 was attributed to JVM UTF-8 URL-decoding behavior rather than fundamentally to Tomcat. Tomcat 4.1.39 introduced a workaround for this and similar encoding issues.
CVE-2008-2370 allowed RequestDispatcher path-normalization behavior to access security-constrained or WEB-INF content in Tomcat 4.1.0 through 4.1.37. It was fixed in Tomcat 4.1.39.
CVE-2008-1232 allowed unfiltered application-controlled data passed to HttpServletResponse.sendError() to inject HTTP-response content and enable XSS. It was fixed in Tomcat 4.1.39.
CVE-2008-0128 affected Tomcat 4.1.0 through 4.1.37 because the SingleSignOn Valve did not mark the JSESSIONIDSSO cookie as Secure when HTTPS was used. It was fixed in Tomcat 4.1.39.
CVE-2007-5461 affected WebDAV configurations with write access and could return arbitrary host files when crafted requests included an entity with a SYSTEM tag. The issue was fixed in Tomcat 4.1.37.
CVE-2007-3382, CVE-2007-3385, and CVE-2007-5333 could leak session information because of incorrect parsing of quote and backslash sequences in cookie values.
CVE-2007-1858 affected Tomcat 4.1.28 through 4.1.31 because the default SSL configuration allowed insecure cipher suites, including anonymous ciphers.
CVE-2007-0450 allowed backslash or encoded-slash path delimiters to bypass proxy context restrictions in Tomcat deployments behind proxies. Tomcat added ALLOW_ENCODED_SLASH and ALLOW_BACKSLASH controls, while noting a related Apache HTTP Server JK connector fix was required.
Multiple XSS issues—CVE-2005-4838, CVE-2006-7196, CVE-2007-1355, CVE-2007-2449, CVE-2007-2450, and CVE-2007-3383—resulted from failures to escape user-controlled output in documentation, examples, calendar, SendMailServlet, or Manager applications. Apache advised against installing example applications in production and identified logout as a mitigation for the Manager issue.
CVE-2005-4836 affected Tomcat 4.1.15 through 4.1.SVN when the deprecated HTTP/1.1 connector was used with allowLinking="true"; null bytes in request URIs could disclose JSP source. Apache recommended the supported Coyote HTTP/1.1 connector and did not plan a Tomcat 4.1.x update.
In response to CVE-2005-3510 and CVE-2006-3835, concerning directory-listing exposure and denial of service from expensive directory-list generation, Tomcat changed directory listings to be disabled by default.
CVE-2005-3164 allowed the deprecated AJP connector to process a request using the preceding request's body after a client disconnected before sending its declared body. The issue was fixed in Tomcat 4.1.37.
CVE-2005-2090 affected Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34. Inconsistent handling of multiple Content-Length headers across intermediaries could enable cache poisoning, XSS, and disclosure of other users' request data.
CVE-2002-1567 allowed newline characters in a requested URL to be reflected in a 404 response header and enable XSS. Tomcat remediated the issue by replacing unsafe response-header characters with spaces.
CVE-2002-0935 and CVE-2003-0866 allowed malformed HTTP requests to leave request-processing threads unresponsive, causing denial of service.
CVE-2002-1148 and CVE-2002-1394 allowed specially crafted URLs involving the default or invoker servlet to disclose JSP source and, in some cases, protected static resources.
CVE-2002-0493 could allow Tomcat to start without its configured security manager if web.xml parsing errors occurred in pre-release Tomcat 4.0.0 builds.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.