Логотип exploitDog
bind:"GHSA-3vx3-xf6q-r5xp" OR bind:"CVE-2017-5648"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-3vx3-xf6q-r5xp" OR bind:"CVE-2017-5648"

Количество 10

Количество 10

github логотип

GHSA-3vx3-xf6q-r5xp

около 3 лет назад

Exposure of Resource to Wrong Sphere in Apache Tomcat

CVSS3: 9.1
EPSS: Средний
ubuntu логотип

CVE-2017-5648

около 8 лет назад

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.

CVSS3: 9.1
EPSS: Средний
redhat логотип

CVE-2017-5648

около 8 лет назад

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.

CVSS3: 3.6
EPSS: Средний
nvd логотип

CVE-2017-5648

около 8 лет назад

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.

CVSS3: 9.1
EPSS: Средний
debian логотип

CVE-2017-5648

около 8 лет назад

While investigating bug 60718, it was noticed that some calls to appli ...

CVSS3: 9.1
EPSS: Средний
oracle-oval логотип

ELSA-2017-1809

почти 8 лет назад

ELSA-2017-1809: tomcat security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:1292-1

около 8 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1382-1

около 8 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1229-1

около 8 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1660-1

почти 8 лет назад

Security update for tomcat

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3vx3-xf6q-r5xp

Exposure of Resource to Wrong Sphere in Apache Tomcat

CVSS3: 9.1
19%
Средний
около 3 лет назад
ubuntu логотип
CVE-2017-5648

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.

CVSS3: 9.1
19%
Средний
около 8 лет назад
redhat логотип
CVE-2017-5648

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.

CVSS3: 3.6
19%
Средний
около 8 лет назад
nvd логотип
CVE-2017-5648

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.

CVSS3: 9.1
19%
Средний
около 8 лет назад
debian логотип
CVE-2017-5648

While investigating bug 60718, it was noticed that some calls to appli ...

CVSS3: 9.1
19%
Средний
около 8 лет назад
oracle-oval логотип
ELSA-2017-1809

ELSA-2017-1809: tomcat security update (IMPORTANT)

почти 8 лет назад
suse-cvrf логотип
openSUSE-SU-2017:1292-1

Security update for tomcat

около 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:1382-1

Security update for tomcat

около 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:1229-1

Security update for tomcat

около 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:1660-1

Security update for tomcat

почти 8 лет назад

Уязвимостей на страницу