cbcvebase.
CVE-2018-11784
published 2018-10-04

CVE-2018-11784: When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g…

medium4.3CVSS 3.0
AVNACLPRNUIRSUCNILAN
EXPLOIT
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
apachetomcat
apachetomcat
apachetomcat7.0.23 – 7.0.90
apachetomcat8.5.0 – 8.5.33
apachetomcat9.0.1 – 9.0.11
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiantomcat9
hynmulti-tenant>= 5.6.0 < 5.7.25.7.2
oraclecommunications_application_session_controller
oraclecommunications_application_session_controller
oraclehospitality_guest_access
oraclehospitality_guest_access
oracleinstantis_enterprisetrack
oracleinstantis_enterprisetrack
oracleinstantis_enterprisetrack
oracleretail_order_broker
oracleretail_order_broker
oracleretail_order_broker
oraclesecure_global_desktop
redhatenterprise_linux_desktop

CVSS provenance

nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
ghsa4.3MEDIUM
osv4.3MEDIUM