CVE-2018-11784

Aliases:GHSA-5q99-f34m-67gc
Advisory lineage Upstream: 0 Downstream: 20
Modified
Published: 04 Oct 2018, 13:00
Last modified:16 Sept 2024, 17:04

Vulnerability Summary

Overall Risk (default)
medium
44/100
CVSS Score
4.3 MEDIUM
v3.0 (nvd)
EPSS Score
82.62% CRITICAL
83% probability -2.49%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

04 Oct 2018, 13:00
Published
Vulnerability first disclosed
16 Sept 2024, 17:04
Last Modified
Vulnerability information updated

Description

When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.

CVSS Metrics

  • v3.0MEDIUMScore: 4.3CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 82.62% Percentile: 99%

Techniques & Countermeasures

  • CWE-601URL Redirection to Untrusted Site ('Open Redirect')

    The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Affected Systems

  • apache software foundationapache tomcat

    9.0.0.M1 to 9.0.11 | 8.5.0 to 8.5.33 | 7.0.23 to 7.0.90

  • UnknownTomcat

    ≥ 7.0.23, ≤ 7.0.90 | ≥ 8.5.0, ≤ 8.5.33 | ≥ 9.0.1, ≤ 9.0.11 | 9.0.0 | 9.0.0:milestone1 | 9.0.0:milestone10 | 9.0.0:milestone11 | 9.0.0:milestone12 | 9.0.0:milestone13 | 9.0.0:milestone14 | 9.0.0:milestone15 | 9.0.0:milestone16 | 9.0.0:milestone17 | 9.0.0:milestone18 | 9.0.0:milestone19 | 9.0.0:milestone2 | 9.0.0:milestone20 | 9.0.0:milestone21 | 9.0.0:milestone22 | 9.0.0:milestone23 | 9.0.0:milestone24 | 9.0.0:milestone25 | 9.0.0:milestone26 | 9.0.0:milestone27 | 9.0.0:milestone3 | 9.0.0:milestone4 | 9.0.0:milestone5 | 9.0.0:milestone6 | 9.0.0:milestone7 | 9.0.0:milestone8 | 9.0.0:milestone9

  • canonicalubuntu_linux

    14.04 | 16.04

  • debiandebian_linux

    8.0

  • org.apache.tomcat.embedtomcat-embed-core

    ≥ 8.5.0, < 8.5.34 | ≥ 7.0.23, < 7.0.91 | ≥ 9.0.0, < 9.0.12

  • netappsnap_creator_framework

    na

  • oraclecommunications_application_session_controller

    3.7.1 | 3.8.0

  • oraclehospitality_guest_access

    4.2.0 | 4.2.1

  • oracleinstantis_enterprisetrack

    17.1 | 17.2 | 17.3

  • oracleretail_order_broker

    5.1 | 5.2 | 15.0

  • oraclesecure_global_desktop

    5.4

  • redhatenterprise_linux_desktop

    7.0

  • redhatenterprise_linux_server

    7.0 | 7.6

  • redhatenterprise_linux_server_aus

    7.6

  • redhatenterprise_linux_server_eus

    7.6

  • redhatenterprise_linux_server_tus

    7.6

  • redhatenterprise_linux_workstation

    7.0

References (67)