Логотип exploitDog
product: "tomcat"
Консоль
Логотип exploitDog

exploitDog

product: "tomcat"
Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

8.08.5910.010.111.02014201520162017201820192020202120222023202420252026

Недавние уязвимости Tomcat

Количество 1 243

nvd логотип

CVE-2011-1183

больше 14 лет назад

Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2011-1183

больше 14 лет назад

Apache Tomcat 7.0.11, when web.xml has no login configuration, does no ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2011-1475

больше 14 лет назад

The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2011-1183

больше 14 лет назад

Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2011-1475

больше 14 лет назад

The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2011-1419

больше 14 лет назад

Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.

CVSS2: 5.8
EPSS: Средний
debian логотип

CVE-2011-1419

больше 14 лет назад

Apache Tomcat 7.x before 7.0.11, when web.xml has no security constrai ...

CVSS2: 5.8
EPSS: Средний
nvd логотип

CVE-2011-1088

больше 14 лет назад

Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.

CVSS2: 5.8
EPSS: Средний
debian логотип

CVE-2011-1088

больше 14 лет назад

Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annota ...

CVSS2: 5.8
EPSS: Средний
redhat логотип

CVE-2011-1582

больше 14 лет назад

Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.

CVSS2: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2011-1183

Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.

CVSS2: 5.8
1%
Низкий
больше 14 лет назад
debian логотип
CVE-2011-1183

Apache Tomcat 7.0.11, when web.xml has no login configuration, does no ...

CVSS2: 5.8
1%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-1475

The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."

CVSS2: 5
12%
Средний
больше 14 лет назад
ubuntu логотип
CVE-2011-1183

Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.

CVSS2: 5.8
1%
Низкий
больше 14 лет назад
redhat логотип
CVE-2011-1475

The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."

CVSS2: 4.3
12%
Средний
больше 14 лет назад
nvd логотип
CVE-2011-1419

Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.

CVSS2: 5.8
16%
Средний
больше 14 лет назад
debian логотип
CVE-2011-1419

Apache Tomcat 7.x before 7.0.11, when web.xml has no security constrai ...

CVSS2: 5.8
16%
Средний
больше 14 лет назад
nvd логотип
CVE-2011-1088

Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.

CVSS2: 5.8
14%
Средний
больше 14 лет назад
debian логотип
CVE-2011-1088

Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annota ...

CVSS2: 5.8
14%
Средний
больше 14 лет назад
redhat логотип
CVE-2011-1582

Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.

CVSS2: 5.8
2%
Низкий
больше 14 лет назад

Уязвимостей на страницу


Поделиться