PT-2018-2771 · Apache+8 · Apache Tomcat+8

Publicado

2018-01-01

·

Atualizado

2024-06-15

·

CVE-2018-11784

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 7.0.23 through 7.0.90 Apache Tomcat versions 8.5.0 through 8.5.33 Apache Tomcat versions 9.0.0.M1 through 9.0.11
Description The default servlet in Apache Tomcat is affected by an open redirect issue. This allows an attacker to use a specially crafted URL to cause the redirect to be generated to any URI of their choice, potentially compromising the integrity of protected information.
Recommendations For Apache Tomcat versions 7.0.23 through 7.0.90, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 8.5.0 through 8.5.33, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 9.0.0.M1 through 9.0.11, update to a version outside of this range to resolve the issue.

Exploit

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2019:1529
ALSA-2019_1529
ALT-PU-2019-1516
BDU:2019-01767
CESA-2019_0485
CESA-2019_1529
CVE-2018-11784
DLA-1544-1
DLA-1545-1
DSA-4596-1
ELSA-2019-0485
ELSA-2019-1529
GHSA-5Q99-F34M-67GC
MGASA-2018-0479
OPENSUSE-SU-2018_3453-1
OPENSUSE-SU-2018_4042-1
OPENSUSE-SU-2019:1547-1
OPENSUSE-SU-2019:1814-1
OPENSUSE-SU-2019_0084-1
OPENSUSE-SU-2019_1547-1
OPENSUSE-SU-2019_1814-1
OPENSUSE-SU-2024:11468-1
OPENSUSE-SU-2024:11501-1
OPENSUSE-SU-2024:13441-1
RHSA-2018:2868
RHSA-2019:0131
RHSA-2019:0485
RHSA-2019:1529
RHSA-2019_0485
RHSA-2019_1529
RLSA-2019:1529
RLSA-2019_1529
SUSE-SU-2018:3261-1
SUSE-SU-2018:3388-1
SUSE-SU-2018:3393-1
SUSE-SU-2018:3935-1
SUSE-SU-2018:3968-1
SUSE-SU-2018_3261-1
SUSE-SU-2018_3388-1
SUSE-SU-2018_3393-1
SUSE-SU-2018_3935-1
SUSE-SU-2018_3968-1
USN-3787-1

Produtos afetados

Alt Linux
Almalinux
Apache Tomcat
Centos
Oracle Database
Red Hat
Rocky Linux
Suse
Ubuntu