# CVE-2003-0043

## Summary

- **CVE ID:** CVE-2003-0043
- **Severity:** UNKNOWN
- **CVSS Score:** 0.09
- **CWE:** N/A
- **Published:** Sep 1, 2004
- **Last Modified:** Mar 16, 2026

## Description

Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](http://www.debian.org/security/2003/dsa-246)
- [CNA](http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/)
- [CNA](http://www.securityfocus.com/advisories/5111)
- [CNA](http://www.ciac.org/ciac/bulletins/n-060.shtml)
- [CNA](http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt)
- [CNA](http://www.securityfocus.com/bid/6722)
- [CNA](https://exchange.xforce.ibmcloud.com/vulnerabilities/11195)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 2.26%
- **EPSS Percentile:** 84.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._