peter bassill · operator
$ cve CVE-2018-11784 JSON

CVE-2018-11784 EXPLOIT

4.3
MEDIUM · CVSS 3.0 · EPSS 97.7% (pctl 100)

Patch early

A public exploit exists.

Description

When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.

Scoring

CVSS4.3 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS97.68% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-601
On CISA KEVno
Public exploityes
Published2018-10-04
Last modified2026-06-17

Affected (15)

VendorProduct
apachetomcat
canonicalubuntu linux
debiandebian linux
netappsnap creator framework
oraclecommunications application session controller
oraclehospitality guest access
oracleinstantis enterprisetrack
oracleretail order broker
oraclesecure global desktop
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation

Public exploits

SourceTitleDate
exploit-dbApache Tomcat 9.0.0.M1 - Open Redirect2021-07-13

References

→ the Explorer  ·  watch your stack  ·  NVD