Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

9.010.010.111.0201720182019202020212022202320242025202620272028

Недавние уязвимости Tomcat

Количество 1 466

redhat логотип

CVE-2013-6357

больше 12 лет назад

Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a /manager/html/undeploy?path= URI. NOTE: the vendor disputes the significance of this report, stating that "the Apache Tomcat Security team has not accepted any reports of CSRF attacks against the Manager application ... as they require a reckless system administrator.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2013-2185

почти 13 лет назад

The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186. NOTE: this issue is reportedly disputed by the Apache Tomcat team, although Red Hat considers it a vulnerability. The dispute appears to regard whether it is the responsibility of applications to avoid providing untrusted data to be deserialized, or whether this class should inherently protect against this issue

CVSS2: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2013-0964

около 13 лет назад

ELSA-2013-0964: tomcat6 security update (MODERATE)

EPSS: Низкий
nvd логотип

CVE-2013-2071

около 13 лет назад

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2013-2071

около 13 лет назад

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7 ...

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2013-2067

около 13 лет назад

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2013-2067

около 13 лет назад

java/org/apache/catalina/authenticator/FormAuthenticator.java in the f ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-3544

около 13 лет назад

Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2012-3544

около 13 лет назад

Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properl ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2013-2071

около 13 лет назад

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.

CVSS2: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2013-6357

Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a /manager/html/undeploy?path= URI. NOTE: the vendor disputes the significance of this report, stating that "the Apache Tomcat Security team has not accepted any reports of CSRF attacks against the Manager application ... as they require a reckless system administrator.

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
redhat логотип
CVE-2013-2185

The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186. NOTE: this issue is reportedly disputed by the Apache Tomcat team, although Red Hat considers it a vulnerability. The dispute appears to regard whether it is the responsibility of applications to avoid providing untrusted data to be deserialized, or whether this class should inherently protect against this issue

CVSS2: 7.5
7%
Низкий
почти 13 лет назад
oracle-oval логотип
ELSA-2013-0964

ELSA-2013-0964: tomcat6 security update (MODERATE)

7%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-2071

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.

CVSS2: 2.6
7%
Низкий
около 13 лет назад
debian логотип
CVE-2013-2071

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7 ...

CVSS2: 2.6
7%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-2067

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

CVSS2: 6.8
7%
Низкий
около 13 лет назад
debian логотип
CVE-2013-2067

java/org/apache/catalina/authenticator/FormAuthenticator.java in the f ...

CVSS2: 6.8
7%
Низкий
около 13 лет назад
nvd логотип
CVE-2012-3544

Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.

CVSS2: 5
11%
Средний
около 13 лет назад
debian логотип
CVE-2012-3544

Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properl ...

CVSS2: 5
11%
Средний
около 13 лет назад
ubuntu логотип
CVE-2013-2071

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.

CVSS2: 2.6
7%
Низкий
около 13 лет назад

Уязвимостей на страницу


Поделиться