Логотип exploitDog
bind:CVE-2018-1304
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-1304

Количество 12

Количество 12

ubuntu логотип

CVE-2018-1304

больше 7 лет назад

The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2018-1304

больше 7 лет назад

The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-1304

больше 7 лет назад

The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2018-1304

больше 7 лет назад

The URL pattern of "" (the empty string) which exactly maps to the con ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-6rxj-58jh-436r

больше 6 лет назад

Apache Tomcat unauthorized access vulnerability

CVSS3: 5.9
EPSS: Низкий
fstec логотип

BDU:2019-01759

больше 7 лет назад

Уязвимость сервера приложений Apache Tomcat, связанная с ошибками в настройках безопасности, позволяющая нарушителю получить доступ к ресурсам веб-приложений

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:1847-1

почти 7 лет назад

Security update for tomcat6

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:0852-1

около 7 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:0817-1

около 7 лет назад

Security update for tomcat

EPSS: Низкий
oracle-oval логотип

ELSA-2019-2205

почти 6 лет назад

ELSA-2019-2205: tomcat security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:3261-1

больше 6 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:3388-1

больше 6 лет назад

Security update for tomcat

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-1304

The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.

CVSS3: 5.9
2%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-1304

The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.

CVSS3: 6.5
2%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-1304

The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.

CVSS3: 5.9
2%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-1304

The URL pattern of "" (the empty string) which exactly maps to the con ...

CVSS3: 5.9
2%
Низкий
больше 7 лет назад
github логотип
GHSA-6rxj-58jh-436r

Apache Tomcat unauthorized access vulnerability

CVSS3: 5.9
2%
Низкий
больше 6 лет назад
fstec логотип
BDU:2019-01759

Уязвимость сервера приложений Apache Tomcat, связанная с ошибками в настройках безопасности, позволяющая нарушителю получить доступ к ресурсам веб-приложений

CVSS3: 5.9
2%
Низкий
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:1847-1

Security update for tomcat6

почти 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:0852-1

Security update for tomcat

около 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:0817-1

Security update for tomcat

около 7 лет назад
oracle-oval логотип
ELSA-2019-2205

ELSA-2019-2205: tomcat security, bug fix, and enhancement update (MODERATE)

почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2018:3261-1

Security update for tomcat

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2018:3388-1

Security update for tomcat

больше 6 лет назад

Уязвимостей на страницу