Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1323

Опубликовано: 12 мар. 2018
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Средний

Описание

The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-worker map did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via IIS, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing Tomcat via the reverse proxy.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:tomcat_jk_connector:*:*:*:*:*:*:*:*
Версия от 1.2.0 (включая) до 1.2.42 (включая)

EPSS

Процентиль: 98%
0.57341
Средний

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-worker map did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via IIS, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing Tomcat via the reverse proxy.

CVSS3: 7.5
redhat
почти 8 лет назад

The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-worker map did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via IIS, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing Tomcat via the reverse proxy.

CVSS3: 7.5
debian
почти 8 лет назад

The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1. ...

CVSS3: 7.5
github
больше 3 лет назад

The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-worker map did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via IIS, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing Tomcat via the reverse proxy.

EPSS

Процентиль: 98%
0.57341
Средний

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22