Skip to main content

Apache Tomcat Default Servlet Error Handling Vulnerability

Last Update Date: 9 Jun 2017 10:09 Release Date: 9 Jun 2017 3965 Views

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

A vulnerability has been identified in Apache Tomcat. A remote user can bypass security controls on the target system.


Impact

  • Security Restriction Bypass

System / Technologies affected

  • 7.0.0 to 7.0.77, 8.0.0.RC1 to 8.0.43, 8.5.0 to 8.5.14, 9.0.0.M1 to 9.0.0.M20

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (7.0.78, 8.0.44, 8.5.15, 9.0.0.M21).

Vulnerability Identifier

  • No CVE information is available

Source


Related Link