Tracker / CVE-2018-11784
CVE-2018-11784
Media 4.3
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.
Prodotti e versioni affette
| apache | tomcat |
|---|---|
| apache | tomcat · 7.0.23 → 7.0.90 |
| apache | tomcat · 8.5.0 → 8.5.33 |
| apache | tomcat · 9.0.1 → 9.0.11 |
| canonical | ubuntu_linux |
| debian | debian_linux |
| netapp | snap_creator_framework |
| oracle | communications_application_session_controller |
| oracle | hospitality_guest_access |
| oracle | instantis_enterprisetrack |
| oracle | retail_order_broker |
| oracle | secure_global_desktop |
| redhat | enterprise_linux_desktop |
| redhat | enterprise_linux_server |
| redhat | enterprise_linux_server_aus |
| redhat | enterprise_linux_server_eus |
| redhat | enterprise_linux_server_tus |
| redhat | enterprise_linux_workstation |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.