Описание
Multiple serious vulnerabilities have been found in Apache Tomcat. Malicious users can exploit these vulnerabilities to bypass security restrictions.
Below is a complete list of vulnerabilities:
- A vulnerability related to security constraints defined by annotations of Servlets can be exploited remotely to bypass security restrictions;
- A vulnerability related URL patterns can be exploited remotely to bypass security restrictions via URL pattern of «»(empty string).
Первичный источник обнаружения
- Apache Tomcat 8.x Security Vulnerabilities
Apache Tomcat 9.x Security Vulnerabilities
Apache Tomcat 7.x Security Vulnerabilities
Связанные продукты
Список CVE
- CVE-2018-1304 warning
- CVE-2018-1305 warning
Смотрите также
Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com
Нашли неточность в описании этой уязвимости? Дайте нам знать!