Apache Software Foundation Apache Ode vulnerabilities
2 known vulnerabilities affecting apache_software_foundation/apache_ode.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2018-1316MEDIUMCVSS 5.0vprior to 1.3.32018-03-05
CVE-2018-1316 [MEDIUM] CVE-2018-1316: The ODE process deployment web service was sensible to deployment messages with forged names
The ODE process deployment web service was sensible to deployment messages with forged names. Using a path for the name was allowing directory traversal, resulting in the potential writing of files under unwanted locations, the overwriting of existing files or their deletion. This issue was addressed in Apache ODE 1.3.3 which was released in 2009, however the incorre
cvelistv5
CVE-2008-2370MEDIUMCVSS 5.0PoCvprior to 1.3.32008-08-04
CVE-2008-2370 [MEDIUM] CWE-22 CVE-2008-2370: Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDi
Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.
nvd