Количество 1 427
Количество 1 427
GHSA-r6cf-cr44-m8rr
Apache Tomcat Leaks Pathname Information via Error Message
GHSA-r29c-68gh-xp6x
Apache Tomcat - HTTP/2 request headers not validated
GHSA-r22m-cc5w-vgh3
** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a /manager/html/undeploy?path= URI. NOTE: the vendor disputes the significance of this report, stating that "the Apache Tomcat Security team has not accepted any reports of CSRF attacks against the Manager application ... as they require a reckless system administrator."
GHSA-qvf5-hvjx-wm27
Apache Tomcat Request and/or response mix-up
GHSA-qrj4-rmqg-4hcp
Apache Tomcat Does Not Properly Handle Empty Requests
GHSA-qrcx-p4rr-g48h
Apache Tomcat allows remote attackers to read JSP source files
GHSA-qqr5-q566-72w2
The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.
GHSA-qq5r-98hh-rxc9
Apache Tomcat - Security constraint bypass with HTTP/0.9
GHSA-qprx-q2r7-3rx6
Improper Input Validation in Apache Tomcat
GHSA-qjw9-54p2-cgcx
The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
GHSA-qg4g-6jcq-rw93
Jakarta Apache Tomcat Reveals Physical Paths
GHSA-qfxv-3ppc-7qg5
Apache Tomcat Vulnerable to Denial of Service (DoS) via Improper Handling of chunk extensions
GHSA-qfw2-wvrw-mvw4
Jakarta Tomcat Directory Listing vulnerability
GHSA-qff8-g48j-pwpw
Apache Tomcat treats single quotes as delimiters in cookies
GHSA-qcxh-w3j9-58qr
Apache Tomcat Denial of Service vulnerability
GHSA-q9xf-jwr4-v445
Authentication Bypass in Apache Tomcat
GHSA-q74x-qqhr-f8rx
Apache Tomcat Cross-site scripting (XSS) vulnerability
GHSA-q4hg-rmq2-52q9
Improper Locking in Apache Tomcat
GHSA-q3mw-pvr8-9ggc
Apache Tomcat Open Redirect vulnerability
GHSA-pxwv-88pv-hh3j
org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-r6cf-cr44-m8rr Apache Tomcat Leaks Pathname Information via Error Message | 7% Низкий | больше 4 лет назад | ||
GHSA-r29c-68gh-xp6x Apache Tomcat - HTTP/2 request headers not validated | CVSS3: 9.8 | 2% Низкий | 3 месяца назад | |
GHSA-r22m-cc5w-vgh3 ** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a /manager/html/undeploy?path= URI. NOTE: the vendor disputes the significance of this report, stating that "the Apache Tomcat Security team has not accepted any reports of CSRF attacks against the Manager application ... as they require a reckless system administrator." | 2% Низкий | около 4 лет назад | ||
GHSA-qvf5-hvjx-wm27 Apache Tomcat Request and/or response mix-up | CVSS3: 6.5 | 2% Низкий | больше 1 года назад | |
GHSA-qrj4-rmqg-4hcp Apache Tomcat Does Not Properly Handle Empty Requests | 5% Низкий | около 4 лет назад | ||
GHSA-qrcx-p4rr-g48h Apache Tomcat allows remote attackers to read JSP source files | 3% Низкий | около 4 лет назад | ||
GHSA-qqr5-q566-72w2 The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension. | 62% Средний | больше 4 лет назад | ||
GHSA-qq5r-98hh-rxc9 Apache Tomcat - Security constraint bypass with HTTP/0.9 | 0% Низкий | 5 месяцев назад | ||
GHSA-qprx-q2r7-3rx6 Improper Input Validation in Apache Tomcat | 7% Низкий | около 4 лет назад | ||
GHSA-qjw9-54p2-cgcx The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie. | 20% Средний | около 4 лет назад | ||
GHSA-qg4g-6jcq-rw93 Jakarta Apache Tomcat Reveals Physical Paths | 26% Средний | больше 4 лет назад | ||
GHSA-qfxv-3ppc-7qg5 Apache Tomcat Vulnerable to Denial of Service (DoS) via Improper Handling of chunk extensions | 11% Средний | около 4 лет назад | ||
GHSA-qfw2-wvrw-mvw4 Jakarta Tomcat Directory Listing vulnerability | 46% Средний | больше 4 лет назад | ||
GHSA-qff8-g48j-pwpw Apache Tomcat treats single quotes as delimiters in cookies | 37% Средний | около 4 лет назад | ||
GHSA-qcxh-w3j9-58qr Apache Tomcat Denial of Service vulnerability | CVSS3: 7.5 | 73% Высокий | около 6 лет назад | |
GHSA-q9xf-jwr4-v445 Authentication Bypass in Apache Tomcat | 9% Низкий | около 4 лет назад | ||
GHSA-q74x-qqhr-f8rx Apache Tomcat Cross-site scripting (XSS) vulnerability | 76% Высокий | около 4 лет назад | ||
GHSA-q4hg-rmq2-52q9 Improper Locking in Apache Tomcat | CVSS3: 7.5 | 73% Высокий | около 7 лет назад | |
GHSA-q3mw-pvr8-9ggc Apache Tomcat Open Redirect vulnerability | CVSS3: 6.1 | 6% Низкий | почти 3 года назад | |
GHSA-pxwv-88pv-hh3j org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response. | 7% Низкий | около 4 лет назад |
Уязвимостей на страницу