Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 429

Количество 1 429

github логотип

GHSA-cww4-vj5r-rx57

около 4 лет назад

Exposure of Sensitive Information in Apache Tomcat

EPSS: Средний
github логотип

GHSA-cw29-r48c-h5f9

около 4 лет назад

org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.

EPSS: Низкий
github логотип

GHSA-cvx5-7vc7-rg77

больше 4 лет назад

Tomcat uses trusted privileges when processing web.xml file

EPSS: Низкий
github логотип

GHSA-cpr9-82wf-f629

около 4 лет назад

java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a large amount of header data.

EPSS: Низкий
github логотип

GHSA-cjg9-7x8h-6gw3

около 4 лет назад

The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.

EPSS: Средний
github логотип

GHSA-c78g-qwpw-2jgv

около 4 лет назад

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

EPSS: Средний
github логотип

GHSA-c5ph-rghf-fjfj

около 1 месяца назад

Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, which fixes the issue.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-c57p-3v2g-w9rg

около 4 лет назад

Insertion of Sensitive Information into Log File in Apache Tomcat

EPSS: Низкий
github логотип

GHSA-c38m-v4m2-524v

около 4 лет назад

Apache Tomcat Allows Remote Attackers to Spoof AJP Requests

EPSS: Средний
github логотип

GHSA-9xrj-439h-62hg

около 4 лет назад

Improper Authentication in Apache Tomcat

EPSS: Низкий
github логотип

GHSA-9m89-8frq-c98c

3 месяца назад

Apache Tomcat - AJP secret compared in non-constant time

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-9m3c-qcxr-9x87

4 месяца назад

Apache Tomcat has an Open Redirect vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-9hjv-9h75-xmpp

около 4 лет назад

Improper Verification of Source of a Communication Channel in Apache Tomcat

CVSS3: 6.3
EPSS: Средний
github логотип

GHSA-9hg2-395j-83rm

около 4 лет назад

Expected Behavior Violation in Apache Tomcat

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-9ggm-7897-x4mg

около 4 лет назад

Improper Input Validation in Apache Tomcat

EPSS: Низкий
github логотип

GHSA-99rf-92v6-cwx4

около 4 лет назад

Improper Access Control in Apache Tomcat

EPSS: Низкий
github логотип

GHSA-9785-w233-x6hv

около 4 лет назад

Improper Resource Shutdown or Release in Apache Tomcat

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-975h-h4pp-737q

около 4 лет назад

The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.

EPSS: Высокий
github логотип

GHSA-9737-qmgc-hfr9

около 4 лет назад

Directory Traversal in Apache Tomcat

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-8wch-9gcg-v2pr

около 4 лет назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Apache Tomcat

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-cww4-vj5r-rx57

Exposure of Sensitive Information in Apache Tomcat

63%
Средний
около 4 лет назад
github логотип
GHSA-cw29-r48c-h5f9

org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.

1%
Низкий
около 4 лет назад
github логотип
GHSA-cvx5-7vc7-rg77

Tomcat uses trusted privileges when processing web.xml file

4%
Низкий
больше 4 лет назад
github логотип
GHSA-cpr9-82wf-f629

java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a large amount of header data.

9%
Низкий
около 4 лет назад
github логотип
GHSA-cjg9-7x8h-6gw3

The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.

18%
Средний
около 4 лет назад
github логотип
GHSA-c78g-qwpw-2jgv

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

42%
Средний
около 4 лет назад
github логотип
GHSA-c5ph-rghf-fjfj

Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, which fixes the issue.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-c57p-3v2g-w9rg

Insertion of Sensitive Information into Log File in Apache Tomcat

1%
Низкий
около 4 лет назад
github логотип
GHSA-c38m-v4m2-524v

Apache Tomcat Allows Remote Attackers to Spoof AJP Requests

15%
Средний
около 4 лет назад
github логотип
GHSA-9xrj-439h-62hg

Improper Authentication in Apache Tomcat

9%
Низкий
около 4 лет назад
github логотип
GHSA-9m89-8frq-c98c

Apache Tomcat - AJP secret compared in non-constant time

CVSS3: 3.7
0%
Низкий
3 месяца назад
github логотип
GHSA-9m3c-qcxr-9x87

Apache Tomcat has an Open Redirect vulnerability

CVSS3: 6.1
1%
Низкий
4 месяца назад
github логотип
GHSA-9hjv-9h75-xmpp

Improper Verification of Source of a Communication Channel in Apache Tomcat

CVSS3: 6.3
11%
Средний
около 4 лет назад
github логотип
GHSA-9hg2-395j-83rm

Expected Behavior Violation in Apache Tomcat

CVSS3: 9.8
8%
Низкий
около 4 лет назад
github логотип
GHSA-9ggm-7897-x4mg

Improper Input Validation in Apache Tomcat

1%
Низкий
около 4 лет назад
github логотип
GHSA-99rf-92v6-cwx4

Improper Access Control in Apache Tomcat

9%
Низкий
около 4 лет назад
github логотип
GHSA-9785-w233-x6hv

Improper Resource Shutdown or Release in Apache Tomcat

CVSS3: 7.5
8%
Низкий
около 4 лет назад
github логотип
GHSA-975h-h4pp-737q

The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.

79%
Высокий
около 4 лет назад
github логотип
GHSA-9737-qmgc-hfr9

Directory Traversal in Apache Tomcat

CVSS3: 5.3
19%
Средний
около 4 лет назад
github логотип
GHSA-8wch-9gcg-v2pr

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Apache Tomcat

11%
Средний
около 4 лет назад

Уязвимостей на страницу