    A security vulnerability has been confirmed to exist in Apache Tomcat 4.0.x releases, which allows to use a specially crafted URL to return the unprocessed source of a JSP page, or, under special circumstances, a static resource which would otherwise have been protected by a security constraint, without the need for being properly authenticated. This is based on a variant of the exploit that was identified as CAN-2002-1148.

  2. My god, this is OLD news...
    Is it another effort by TSS to hurt the Java community?
    BTW, Tomcat's latest version is 4.1.18, and this vulnerability has also been corrected in the latest 4.0.x branch.
    This vulnerabilty only allows to show the source code of JSPs. Anybody with decent Java skills would not put anything important there anyway.
    And Struts users will also put their JSPs under WEB-INF/, which will protect them anyway.
    And normally Tomcat would run behind Apache - the forged URL should not be forwarded to Tomcat. In my conf file it's only forwarding *.do URL for example...
