Логотип exploitDog
product: "tomcat"
Консоль
Логотип exploitDog

exploitDog

product: "tomcat"
Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

8.08.5910.010.111.020142015201620172018201920202021202220232024202520262027

Недавние уязвимости Tomcat

Количество 1 262

debian логотип

CVE-2011-1183

почти 15 лет назад

Apache Tomcat 7.0.11, when web.xml has no login configuration, does no ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2011-1183

почти 15 лет назад

Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2011-1475

почти 15 лет назад

The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2011-1475

почти 15 лет назад

The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2011-1419

почти 15 лет назад

Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.

CVSS2: 5.8
EPSS: Средний
debian логотип

CVE-2011-1419

почти 15 лет назад

Apache Tomcat 7.x before 7.0.11, when web.xml has no security constrai ...

CVSS2: 5.8
EPSS: Средний
nvd логотип

CVE-2011-1088

почти 15 лет назад

Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.

CVSS2: 5.8
EPSS: Средний
debian логотип

CVE-2011-1088

почти 15 лет назад

Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annota ...

CVSS2: 5.8
EPSS: Средний
redhat логотип

CVE-2011-1088

почти 15 лет назад

Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.

CVSS2: 5.8
EPSS: Средний
redhat логотип

CVE-2011-1419

почти 15 лет назад

Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.

CVSS2: 5.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2011-1183

Apache Tomcat 7.0.11, when web.xml has no login configuration, does no ...

CVSS2: 5.8
1%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2011-1183

Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.

CVSS2: 5.8
1%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2011-1475

The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."

CVSS2: 5
12%
Средний
почти 15 лет назад
redhat логотип
CVE-2011-1475

The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."

CVSS2: 4.3
12%
Средний
почти 15 лет назад
nvd логотип
CVE-2011-1419

Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.

CVSS2: 5.8
16%
Средний
почти 15 лет назад
debian логотип
CVE-2011-1419

Apache Tomcat 7.x before 7.0.11, when web.xml has no security constrai ...

CVSS2: 5.8
16%
Средний
почти 15 лет назад
nvd логотип
CVE-2011-1088

Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.

CVSS2: 5.8
22%
Средний
почти 15 лет назад
debian логотип
CVE-2011-1088

Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annota ...

CVSS2: 5.8
22%
Средний
почти 15 лет назад
redhat логотип
CVE-2011-1088

Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.

CVSS2: 5.8
22%
Средний
почти 15 лет назад
redhat логотип
CVE-2011-1419

Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.

CVSS2: 5.8
16%
Средний
почти 15 лет назад

Уязвимостей на страницу


Поделиться