Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 427

Количество 1 427

fstec логотип

BDU:2023-06728

почти 3 года назад

Уязвимость сервера приложений Apache Tomcat существует из-за неполной очистки временных или вспомогательных ресурсов, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2021-03686

около 5 лет назад

Уязвимость реализации модуля JNDIRealm сервера приложений Apache Tomcat, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.8
EPSS: Низкий
fstec логотип

BDU:2021-03688

около 5 лет назад

Уязвимость сервера приложений Apache Tomcat, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю отправить скрытый HTTP-запрос

CVSS3: 5.3
EPSS: Высокий
suse-cvrf логотип

openSUSE-SU-2021:0081-1

больше 5 лет назад

Security update for tomcat

EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2021:0043-1

больше 5 лет назад

Security update for tomcat

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2021:1431-1

больше 5 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0042-1

больше 5 лет назад

Security update for tomcat

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2021:0041-1

больше 5 лет назад

Security update for tomcat

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2021:0031-1

больше 5 лет назад

Security update for tomcat

EPSS: Средний
github логотип

GHSA-vvw4-rfwf-p6hx

больше 4 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-vf77-8h7g-gghp

больше 4 лет назад

Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-jgwr-3qm3-26f3

больше 5 лет назад

Potential remote code execution in Apache Tomcat

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-j39c-c8hj-x4j3

около 5 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2021-25329

больше 5 лет назад

The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2021-25329

больше 5 лет назад

The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2021-25329

больше 5 лет назад

The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.

CVSS3: 7
EPSS: Низкий
debian логотип

CVE-2021-25329

больше 5 лет назад

The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10. ...

CVSS3: 7
EPSS: Низкий
ubuntu логотип

CVE-2021-25122

больше 5 лет назад

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2021-25122

больше 5 лет назад

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2021-25122

больше 5 лет назад

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2023-06728

Уязвимость сервера приложений Apache Tomcat существует из-за неполной очистки временных или вспомогательных ресурсов, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.5
2%
Низкий
почти 3 года назад
fstec логотип
BDU:2021-03686

Уязвимость реализации модуля JNDIRealm сервера приложений Apache Tomcat, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.8
10%
Низкий
около 5 лет назад
fstec логотип
BDU:2021-03688

Уязвимость сервера приложений Apache Tomcat, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю отправить скрытый HTTP-запрос

CVSS3: 5.3
75%
Высокий
около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0081-1

Security update for tomcat

25%
Средний
больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0043-1

Security update for tomcat

25%
Средний
больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:1431-1

Security update for tomcat

9%
Низкий
больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:0042-1

Security update for tomcat

25%
Средний
больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:0041-1

Security update for tomcat

25%
Средний
больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:0031-1

Security update for tomcat

25%
Средний
больше 5 лет назад
github логотип
GHSA-vvw4-rfwf-p6hx

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

CVSS3: 7.5
25%
Средний
больше 4 лет назад
github логотип
GHSA-vf77-8h7g-gghp

Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat

CVSS3: 7.5
64%
Средний
больше 4 лет назад
github логотип
GHSA-jgwr-3qm3-26f3

Potential remote code execution in Apache Tomcat

CVSS3: 7
9%
Низкий
больше 5 лет назад
github логотип
GHSA-j39c-c8hj-x4j3

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

CVSS3: 7.5
18%
Средний
около 5 лет назад
ubuntu логотип
CVE-2021-25329

The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.

CVSS3: 7
9%
Низкий
больше 5 лет назад
redhat логотип
CVE-2021-25329

The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.

CVSS3: 7
9%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-25329

The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.

CVSS3: 7
9%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-25329

The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10. ...

CVSS3: 7
9%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2021-25122

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

CVSS3: 7.5
18%
Средний
больше 5 лет назад
redhat логотип
CVE-2021-25122

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

CVSS3: 7.5
18%
Средний
больше 5 лет назад
nvd логотип
CVE-2021-25122

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

CVSS3: 7.5
18%
Средний
больше 5 лет назад

Уязвимостей на страницу