PT-2021-21718 · Unknown · Ttiny Java Web Server/Servlet Container

Maurizio Ruchay

·

Published

2021-08-09

·

Updated

2021-08-17

·

CVE-2021-37573

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TTiny Java Web Server and Servlet Container (TJWS) versions <=1.115
Description A reflected cross-site scripting (XSS) issue allows an adversary to inject malicious code on the server's "404 Page not Found" error page. This occurs in the web server TTiny Java Web Server and Servlet Container (TJWS).
Recommendations For versions <=1.115, update to a version greater than 1.115 to resolve the issue. As a temporary workaround, consider restricting access to the "404 Page not Found" error page until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37573

Affected Products

Ttiny Java Web Server/Servlet Container