Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

9.010.010.111.0201720182019202020212022202320242025202620272028

Недавние уязвимости Tomcat

Количество 1 533

github логотип

GHSA-79m3-w93m-vjpg

больше 4 лет назад

** DISPUTED ** Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."

EPSS: Низкий
github логотип

GHSA-8h2q-qm9x-55jc

больше 4 лет назад

Denial of Service in Apache Tomcat

EPSS: Средний
github логотип

GHSA-3p86-xgrq-m6p6

больше 4 лет назад

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

EPSS: Средний
github логотип

GHSA-w6q7-ww2x-7gm3

больше 4 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

EPSS: Средний
github логотип

GHSA-975h-h4pp-737q

больше 4 лет назад

The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.

EPSS: Высокий
github логотип

GHSA-8wch-9gcg-v2pr

больше 4 лет назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Apache Tomcat

EPSS: Средний
github логотип

GHSA-hjfh-7c4v-7q8h

больше 4 лет назад

Improper Authentication in Apache Tomcat

EPSS: Низкий
github логотип

GHSA-ggx9-4728-588r

больше 4 лет назад

Apache Tomcat Directory Traversal vulnerability

EPSS: Низкий
github логотип

GHSA-x75h-2jg7-ffxw

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML." NOTE: this is due to a missing fix for CVE-2009-0781.

EPSS: Низкий
github логотип

GHSA-hhjg-g8xq-hhr3

больше 4 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

CVSS3: 4.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-79m3-w93m-vjpg

** DISPUTED ** Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."

1%
Низкий
больше 4 лет назад
github логотип
GHSA-8h2q-qm9x-55jc

Denial of Service in Apache Tomcat

10%
Средний
больше 4 лет назад
github логотип
GHSA-3p86-xgrq-m6p6

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

10%
Средний
больше 4 лет назад
github логотип
GHSA-w6q7-ww2x-7gm3

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

53%
Средний
больше 4 лет назад
github логотип
GHSA-975h-h4pp-737q

The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.

79%
Высокий
больше 4 лет назад
github логотип
GHSA-8wch-9gcg-v2pr

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Apache Tomcat

11%
Средний
больше 4 лет назад
github логотип
GHSA-hjfh-7c4v-7q8h

Improper Authentication in Apache Tomcat

8%
Низкий
больше 4 лет назад
github логотип
GHSA-ggx9-4728-588r

Apache Tomcat Directory Traversal vulnerability

10%
Низкий
больше 4 лет назад
github логотип
GHSA-x75h-2jg7-ffxw

Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML." NOTE: this is due to a missing fix for CVE-2009-0781.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-hhjg-g8xq-hhr3

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

CVSS3: 4.2
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться