Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-12616

Опубликовано: 19 сент. 2017
Источник: ubuntu
Приоритет: medium
EPSS Критический
CVSS2: 5
CVSS3: 7.5

Описание

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

end of standard support, was needed
cosmic

ignored

end of life
devel

DNE

disco

DNE

eoan

DNE

esm-apps/bionic

ignored

see notes
esm-apps/xenial

released

7.0.68-1ubuntu0.4+esm3
esm-infra-legacy/trusty

not-affected

7.0.52-1ubuntu0.14
esm-infra/focal

DNE

Показывать по

РелизСтатусПримечание
artful

not-affected

bionic

not-affected

8.5.30-1ubuntu1
cosmic

not-affected

8.5.30-1ubuntu2
devel

DNE

disco

DNE

eoan

DNE

esm-apps/bionic

not-affected

8.5.30-1ubuntu1
esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

esm-infra/xenial

not-affected

Показывать по

EPSS

Процентиль: 100%
0.91315
Критический

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
почти 8 лет назад

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.

CVSS3: 7.5
nvd
почти 8 лет назад

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.

CVSS3: 7.5
debian
почти 8 лет назад

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it w ...

CVSS3: 7.5
github
около 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

suse-cvrf
больше 7 лет назад

Security update for tomcat

EPSS

Процентиль: 100%
0.91315
Критический

5 Medium

CVSS2

7.5 High

CVSS3