CVE-2018-1305

Aliases:GHSA-jx6h-3fjx-cgv5
Advisory lineage Upstream: 0 Downstream: 12
Modified
Published: 23 Feb 2018, 23:00
Last modified:17 Sept 2024, 01:12

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
6.5 MEDIUM
v3.0 (nvd)
EPSS Score
21.58% HIGH
22% probability +2.31%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Feb 2018, 23:00
Published
Vulnerability first disclosed
17 Sept 2024, 01:12
Last Modified
Vulnerability information updated

Description

Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were loaded - for some security constraints not to be applied. This could have exposed resources to users who were not authorised to access them.

CVSS Metrics

  • v3.0MEDIUMScore: 6.5CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • v2.0MEDIUMScore: 4AV:N/AC:L/Au:S/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 21.58% Percentile: 96%

Affected Systems

  • apache software foundationapache tomcat

    Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49, 7.0.0 to 7.0.84

  • UnknownTomcat

    ≥ 7.0.0, ≤ 7.0.84 | ≥ 8.0.0, ≤ 8.0.49 | 8.0.0:rc1 | 8.0.0:rc10 | 8.0.0:rc3 | 8.0.0:rc5 | 9.0.0 | 9.0.0:milestone1 | 9.0.0:milestone10 | 9.0.0:milestone11 | 9.0.0:milestone12 | 9.0.0:milestone13 | 9.0.0:milestone14 | 9.0.0:milestone15 | 9.0.0:milestone16 | 9.0.0:milestone17 | 9.0.0:milestone18 | 9.0.0:milestone19 | 9.0.0:milestone2 | 9.0.0:milestone20 | 9.0.0:milestone21 | 9.0.0:milestone22 | 9.0.0:milestone23 | 9.0.0:milestone24 | 9.0.0:milestone25 | 9.0.0:milestone26 | 9.0.0:milestone27 | 9.0.0:milestone3 | 9.0.0:milestone4 | 9.0.0:milestone5 | 9.0.0:milestone6 | 9.0.0:milestone7 | 9.0.0:milestone8 | 9.0.0:milestone9 | 9.0.1 | 9.0.2 | 9.0.3 | 9.0.4 | ≥ 8.5.0, ≤ 8.5.27

  • canonicalubuntu_linux

    14.04 | 16.04 | 17.10 | 18.04

  • debiandebian_linux

    7.0 | 8.0 | 9.0

  • org.apache.tomcat.embedtomcat-embed-core

    ≥ 9.0.0M1, < 9.0.5 | ≥ 8.5.0, < 8.5.28 | ≥ 7.0.0, < 7.0.85

  • UnknownFusion Middleware

    12.2.1.3.0

  • oraclemanaged_file_transfer

    12.1.3.0.0 | 12.2.1.3.0

  • oraclemicros_relate_crm_software

    11.4

References (64)