peter bassill · operator
$ cve CVE-2017-5648 JSON

CVE-2017-5648

9.1
CRITICAL · CVSS 3.0 · EPSS 13.2% (pctl 96)

Patch early

EPSS 13.2% — above the 10% action threshold.

Description

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.

Scoring

CVSS9.1 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS13.23% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-668
On CISA KEVno
Public exploitnone known
Published2017-04-17
Last modified2026-06-17

Affected (1)

VendorProduct
apachetomcat

References

→ the Explorer  ·  watch your stack  ·  NVD