Количество 1 427
Количество 1 427
GHSA-pvjh-7h8q-q56r
Apache Tomcat has cookies without HTTPOnly flag in Set-Cookie header
GHSA-prc3-7f44-w48j
Missing XML Validation in Apache Tomcat
GHSA-ppj6-9ppm-3h56
The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).
GHSA-pm78-wxxf-fw98
Cross-site scripting in Apache Tomcat
GHSA-pg42-rg8c-j886
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.
GHSA-p57v-p3fx-qgwm
Apache Tomcat XSS Vulnerability
GHSA-p543-jg43-9pm5
Apache Tomcat may be started without proper security settings
GHSA-p26v-97vp-jcx6
Access controll bypass in Apache Tomcat
GHSA-p263-rh6r-g7jw
Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers.
GHSA-p22x-g9px-3945
Apache Tomcat may reject request containing invalid Content-Length header
GHSA-mxxf-x9fw-f2hv
Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomcat 5.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) el/functions.jsp, (2) el/implicit-objects.jsp, and (3) jspx/textRotate.jspx in examples/jsp2/, as demonstrated via script in a request to snp/snoop.jsp. NOTE: other XSS issues in the manager were simultaneously reported, but these require admin access and do not cross privilege boundaries.
GHSA-mv42-px54-87jw
Improper Access Control in Apache Tomcat
GHSA-mqg3-r7h5-24x4
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119 which fixes the issue.
GHSA-mppv-79ch-vw6q
Apache Tomcat vulnerable to information leak
GHSA-mg4v-rf8p-ghqq
Apache Tomcat allows remote attackers to bypass intended access restrictions
GHSA-m8w6-7rh6-4xj6
Apache Tomcat Leaks Information via Error Message
GHSA-m8h8-6rvg-f4mg
Apache Tomcat Path Traversal Vulnerability
GHSA-m7xj-ccqc-p4g2
Apache Tomcat Directory Traversal vulnerability
GHSA-jxcv-v856-j5vg
Apache Tomcat Source Code Disclosure
GHSA-jx7c-7mj5-9438
Apache Tomcat Race Condition vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-pvjh-7h8q-q56r Apache Tomcat has cookies without HTTPOnly flag in Set-Cookie header | 2% Низкий | около 4 лет назад | ||
GHSA-prc3-7f44-w48j Missing XML Validation in Apache Tomcat | 8% Низкий | около 4 лет назад | ||
GHSA-ppj6-9ppm-3h56 The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null). | 27% Средний | больше 4 лет назад | ||
GHSA-pm78-wxxf-fw98 Cross-site scripting in Apache Tomcat | 72% Высокий | около 4 лет назад | ||
GHSA-pg42-rg8c-j886 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue. | CVSS3: 6.1 | 4% Низкий | около 1 месяца назад | |
GHSA-p57v-p3fx-qgwm Apache Tomcat XSS Vulnerability | 5% Низкий | около 4 лет назад | ||
GHSA-p543-jg43-9pm5 Apache Tomcat may be started without proper security settings | 4% Низкий | больше 4 лет назад | ||
GHSA-p26v-97vp-jcx6 Access controll bypass in Apache Tomcat | 6% Низкий | около 4 лет назад | ||
GHSA-p263-rh6r-g7jw Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers. | 5% Низкий | больше 4 лет назад | ||
GHSA-p22x-g9px-3945 Apache Tomcat may reject request containing invalid Content-Length header | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-mxxf-x9fw-f2hv Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomcat 5.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) el/functions.jsp, (2) el/implicit-objects.jsp, and (3) jspx/textRotate.jspx in examples/jsp2/, as demonstrated via script in a request to snp/snoop.jsp. NOTE: other XSS issues in the manager were simultaneously reported, but these require admin access and do not cross privilege boundaries. | 8% Низкий | около 4 лет назад | ||
GHSA-mv42-px54-87jw Improper Access Control in Apache Tomcat | CVSS3: 8.8 | 13% Средний | около 4 лет назад | |
GHSA-mqg3-r7h5-24x4 Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119 which fixes the issue. | CVSS3: 9.1 | 1% Низкий | около 1 месяца назад | |
GHSA-mppv-79ch-vw6q Apache Tomcat vulnerable to information leak | CVSS3: 7.5 | 1% Низкий | около 3 лет назад | |
GHSA-mg4v-rf8p-ghqq Apache Tomcat allows remote attackers to bypass intended access restrictions | 6% Низкий | около 4 лет назад | ||
GHSA-m8w6-7rh6-4xj6 Apache Tomcat Leaks Information via Error Message | 7% Низкий | больше 4 лет назад | ||
GHSA-m8h8-6rvg-f4mg Apache Tomcat Path Traversal Vulnerability | 53% Средний | около 4 лет назад | ||
GHSA-m7xj-ccqc-p4g2 Apache Tomcat Directory Traversal vulnerability | 100% Критический | около 4 лет назад | ||
GHSA-jxcv-v856-j5vg Apache Tomcat Source Code Disclosure | 17% Средний | больше 4 лет назад | ||
GHSA-jx7c-7mj5-9438 Apache Tomcat Race Condition vulnerability | CVSS3: 3.7 | 2% Низкий | почти 4 года назад |
Уязвимостей на страницу