{ "canonical_id": "apache-tomcat--CVE-2002-2009", "system_id": "apache-tomcat", "display_name": "Apache Tomcat", "category": "servers", "advisory_mode": "server", "title": "CVE-2002-2009", "summary": "Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3)