Логотип exploitDog
bind:"CVE-2017-5648"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2017-5648"

Количество 10

Количество 10

ubuntu логотип

CVE-2017-5648

больше 8 лет назад

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.

CVSS3: 9.1
EPSS: Средний
redhat логотип

CVE-2017-5648

больше 8 лет назад

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.

CVSS3: 3.6
EPSS: Средний
nvd логотип

CVE-2017-5648

больше 8 лет назад

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.

CVSS3: 9.1
EPSS: Средний
debian логотип

CVE-2017-5648

больше 8 лет назад

While investigating bug 60718, it was noticed that some calls to appli ...

CVSS3: 9.1
EPSS: Средний
github логотип

GHSA-3vx3-xf6q-r5xp

больше 3 лет назад

Exposure of Resource to Wrong Sphere in Apache Tomcat

CVSS3: 9.1
EPSS: Средний
oracle-oval логотип

ELSA-2017-1809

больше 8 лет назад

ELSA-2017-1809: tomcat security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:1292-1

больше 8 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1382-1

больше 8 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1229-1

больше 8 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1660-1

больше 8 лет назад

Security update for tomcat

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-5648

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.

CVSS3: 9.1
19%
Средний
больше 8 лет назад
redhat логотип
CVE-2017-5648

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.

CVSS3: 3.6
19%
Средний
больше 8 лет назад
nvd логотип
CVE-2017-5648

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.

CVSS3: 9.1
19%
Средний
больше 8 лет назад
debian логотип
CVE-2017-5648

While investigating bug 60718, it was noticed that some calls to appli ...

CVSS3: 9.1
19%
Средний
больше 8 лет назад
github логотип
GHSA-3vx3-xf6q-r5xp

Exposure of Resource to Wrong Sphere in Apache Tomcat

CVSS3: 9.1
19%
Средний
больше 3 лет назад
oracle-oval логотип
ELSA-2017-1809

ELSA-2017-1809: tomcat security update (IMPORTANT)

больше 8 лет назад
suse-cvrf логотип
openSUSE-SU-2017:1292-1

Security update for tomcat

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:1382-1

Security update for tomcat

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:1229-1

Security update for tomcat

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:1660-1

Security update for tomcat

больше 8 лет назад

Уязвимостей на страницу