Описание
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Релиз | Статус | Примечание |
---|---|---|
artful | DNE | |
bionic | DNE | |
cosmic | DNE | |
devel | DNE | |
disco | DNE | |
eoan | DNE | |
esm-apps/xenial | not-affected | 6.0.39-1 |
esm-infra-legacy/trusty | not-affected | 6.0.39-1 |
esm-infra/focal | DNE | |
focal | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
artful | not-affected | 7.0.52-1 |
bionic | not-affected | 7.0.52-1 |
cosmic | not-affected | 7.0.52-1 |
devel | DNE | |
disco | DNE | |
eoan | DNE | |
esm-apps/bionic | not-affected | 7.0.52-1 |
esm-apps/xenial | not-affected | 7.0.52-1 |
esm-infra-legacy/trusty | not-affected | 7.0.52-1 |
esm-infra/focal | DNE |
Показывать по
4.3 Medium
CVSS2
Связанные уязвимости
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-R ...
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
4.3 Medium
CVSS2