CVE-2007-5366
CVE-2007-5366 is a medium-severity vulnerability in Fujitsu Interstage Application Server with a CVSS 2.0 base score of 5.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Medium (CVSS 2.0 base score 5.0)
- EPSS exploit prediction: 2% (82nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-22
- Affected product: Fujitsu Interstage Application Server
- Published:
- Last modified:
Description
The Tomcat 4.1-based Servlet Service in Fujitsu Interstage Application Server 7.0 through 9.0.0 and Interstage Apworks/Studio 7.0 through 9.0.0 allows remote attackers to obtain sensitive information (web root path) via unspecified vectors that trigger an error message, probably related to enabling the useCanonCaches Java Virtual Machine (JVM) option.
Frequently asked questions
- What is CVE-2007-5366?
- The Tomcat 4.1-based Servlet Service in Fujitsu Interstage Application Server 7.0 through 9.0.0 and Interstage Apworks/Studio 7.0 through 9.0.0 allows remote attackers to obtain sensitive information (web root path) via unspecified vectors that trigger an error message, probably related to enabling the useCanonCaches Java Virtual Machine (JVM) option.
- How severe is CVE-2007-5366?
- CVE-2007-5366 has a CVSS 2.0 base score of 5.0, rated medium severity.
- Is CVE-2007-5366 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (82nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2007-5366?
- CVE-2007-5366 primarily affects Fujitsu Interstage Application Server. In total, 24 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2007-5366?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2007-5366 published?
- CVE-2007-5366 was published on 2007-10-11 and last updated on 2026-06-16.
References
- http://osvdb.org/41318
- http://secunia.com/advisories/27136
- http://www.fujitsu.com/global/support/software/security/products-f/interstage-200705e.html
- http://www.securityfocus.com/bid/25988
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37026
Affected products (24)
- cpe:2.3:a:fujitsu:interstage_application_server:7.0:*:enterprise:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_application_server:7.0:*:plus:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_application_server:7.0:*:plus_developer:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_application_server:7.0.1:*:enterprise:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_application_server:7.0.1:*:plus:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_application_server:8.0.0:*:enterprise:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_application_server:8.0.0:*:standard_j:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_application_server:8.0.1:*:enterprise:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_application_server:8.0.1:*:standard_j:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_application_server:8.0.2:*:enterprise:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_application_server:8.0.2:*:standard_j:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_application_server:8.0.3:*:enterprise:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_application_server:8.0.3:*:standard_j:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_application_server:9.0:*:enterprise:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_application_server:9.0:*:standard_j:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_application_server:9.0a:*:enterprise:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_application_server:9.0a:*:standard_j:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_apworks:7.0:*:modelers_j:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_apworks:8.0:*:enterprise:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_apworks:8.0:*:standard_j:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_studio:8.01:*:enterprise:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_studio:8.01:*:standard_j:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_studio:9.0:*:enterprise:*:*:*:*:*
- cpe:2.3:a:fujitsu:interstage_studio:9.0:*:standard_j:*:*:*:*:*
More vulnerabilities in Fujitsu Interstage Application Server
- CVE-2013-7105 — Critical (CVSS 10.0): Buffer overflow in the Interstage HTTP Server log functionality, as used in Fujitsu Interstage Application Server…
- CVE-2010-1942 — Medium (CVSS 6.4): Unspecified vulnerability in the Servlet service in Fujitsu Limited Interstage Application Server 3.0 through 7.0, as…
- CVE-2019-13163 — Medium (CVSS 5.9): The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle…
- CVE-2008-7195 — Medium (CVSS 5.0): Unspecified vulnerability in Fujitsu Interstage HTTP Server, as used in Interstage Application Server Enterprise…
- CVE-2008-7194 — Medium (CVSS 5.0): Unspecified vulnerability in Fujitsu Interstage HTTP Server, as used in Interstage Application Server 5.0, 7.0, 7.0.1,…
- CVE-2007-1504 — Medium (CVSS 4.3): Cross-site scripting (XSS) vulnerability in the Servlet Service in Fujitsu Interstage Application Server (IJServer)…
All CVEs affecting Fujitsu Interstage Application Server →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-80155 — Critical (CVSS 10.0): Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of…
- CVE-2026-70200 — Critical (CVSS 10.0): Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an…
- CVE-2026-85706 — Critical (CVSS 10.0): GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and…
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.
- CVE-2026-18051 — Critical (CVSS 10.0): The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache…
- CVE-2026-74764 — Critical (CVSS 10.0): Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a…