Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 429

Количество 1 429

fstec логотип

BDU:2022-03062

больше 4 лет назад

Уязвимость сервера приложений Apache Tomcat, связанная с ошибками при одновременном закрытии соединения WebSocket и отправки сообщения WebSocket, позволяющая нарушителю раскрыть защищаемую информацию или оказать другое воздействие

CVSS3: 8.6
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:0818-1

больше 4 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0818-1

больше 4 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0784-1

больше 4 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0695-1

больше 4 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0694-1

больше 4 лет назад

Security update for tomcat

EPSS: Низкий
github логотип

GHSA-r4x2-3cq5-hqvp

почти 8 лет назад

The defaults settings for the CORS filter provided in Apache Tomcat are insecure and enable 'supportsCredentials' for all origins

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-q6x7-f33r-3wxx

около 4 лет назад

Incorrect Authorization in Apache Tomcat

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9f3j-pm6f-9fm5

больше 4 лет назад

Race condition in Apache Tomcat

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-36qh-35cm-5w2w

почти 5 лет назад

Authentication Bypass by Alternate Name in Apache Tomcat

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2rvf-329f-p99g

около 4 лет назад

System Property Disclosure in Apache Tomcat

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-23181

больше 4 лет назад

The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2022-23181

больше 4 лет назад

The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2022-23181

больше 4 лет назад

The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.

CVSS3: 7
EPSS: Низкий
debian логотип

CVE-2022-23181

больше 4 лет назад

The fix for bug CVE-2020-9484 introduced a time of check, time of use ...

CVSS3: 7
EPSS: Низкий
ubuntu логотип

CVE-2021-30640

около 5 лет назад

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2021-30640

около 5 лет назад

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-30640

около 5 лет назад

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-30640

около 5 лет назад

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2018-8014

около 8 лет назад

The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2022-03062

Уязвимость сервера приложений Apache Tomcat, связанная с ошибками при одновременном закрытии соединения WebSocket и отправки сообщения WebSocket, позволяющая нарушителю раскрыть защищаемую информацию или оказать другое воздействие

CVSS3: 8.6
8%
Низкий
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2022:0818-1

Security update for tomcat

1%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:0818-1

Security update for tomcat

1%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:0784-1

Security update for tomcat

1%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:0695-1

Security update for tomcat

1%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:0694-1

Security update for tomcat

1%
Низкий
больше 4 лет назад
github логотип
GHSA-r4x2-3cq5-hqvp

The defaults settings for the CORS filter provided in Apache Tomcat are insecure and enable 'supportsCredentials' for all origins

CVSS3: 9.8
22%
Средний
почти 8 лет назад
github логотип
GHSA-q6x7-f33r-3wxx

Incorrect Authorization in Apache Tomcat

CVSS3: 7.5
8%
Низкий
около 4 лет назад
github логотип
GHSA-9f3j-pm6f-9fm5

Race condition in Apache Tomcat

CVSS3: 7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-36qh-35cm-5w2w

Authentication Bypass by Alternate Name in Apache Tomcat

CVSS3: 6.5
10%
Низкий
почти 5 лет назад
github логотип
GHSA-2rvf-329f-p99g

System Property Disclosure in Apache Tomcat

CVSS3: 5.3
7%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-23181

The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.

CVSS3: 7
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-23181

The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.

CVSS3: 7
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-23181

The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.

CVSS3: 7
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-23181

The fix for bug CVE-2020-9484 introduced a time of check, time of use ...

CVSS3: 7
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-30640

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.

CVSS3: 6.5
10%
Низкий
около 5 лет назад
redhat логотип
CVE-2021-30640

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.

CVSS3: 6.5
10%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-30640

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.

CVSS3: 6.5
10%
Низкий
около 5 лет назад
debian логотип
CVE-2021-30640

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker ...

CVSS3: 6.5
10%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2018-8014

The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.

CVSS3: 9.8
22%
Средний
около 8 лет назад

Уязвимостей на страницу