BDU:2019-01767

Scores

EPSS

0.000none0.0%
0%20%40%60%80%100%

Percentile: 0.0%

CVSS

4.3medium3.x
0246810

CVSS Score: 4.3/10

All CVSS Scores

CVSS 3.x
4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CVSS 2.0
4.3

Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Description

Уязвимость сервлета по умолчанию сервера приложений Apache Tomcat связана с использованием открытой переадресации. Эксплуатация уязвимости может позволить нарушителю, действующему удалённо, оказать воздействие на целостность защищаемой информации

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

bdu

Related Vulnerabilities

Exploits

Exploit ID: 50118

Source: exploitdb

URL: https://www.exploit-db.com/exploits/50118

Exploit ID: CVE-2018-11784

Source: github-poc

URL: https://github.com/Cappricio-Securities/CVE-2018-11784

Reference Links

Recommendations

Source: bdu

Использование рекомендаций:
Для Apache:
https://lists.apache.org/thread.html/eb6efa8d59c45a7a9eff94c4b925467d3b3fec8ba7697f3daa314b04@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/5c0e00fd31efc11e147bf99d0f03c00a734447d3b131ab0818644cdb@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/23134c9b5a23892a205dc140cdd8c9c0add233600f76b313dda6bd75@%3Cannounce.tomcat.apache.org%3E
https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551@%3Cdev.tomcat.apache.org%3E

Для программных продуктов Novell Inc.:
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00030.html
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00056.html

Для McAfee Enterprise Security Manager:
https://kc.mcafee.com/corporate/index?page=content&id=SB10284

Для Debian:
https://lists.debian.org/debian-lts-announce/2018/10/msg00005.html
https://lists.debian.org/debian-lts-announce/2018/10/msg00006.html

Для Fedora:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BZ4PX4B3QTKRM35VJAVIEOPZAF76RPBP/

Для Ubuntu:
https://usn.ubuntu.com/3787-1/

Для программных продуктов Oracle:
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
https://www.oracle.com/security-alerts/cpuoct2019.html
https://www.oracle.com/security-alerts/cpujan2020.html

Для программных продуктов Red Hat:
https://access.redhat.com/security/cve/CVE-2018-11784

Для ОС ОН «Стрелец»:
Обновление программного обеспечения tomcat8 до версии 8.5.54-0+deb9u8

URL: https://bdu.fstec.ru/vul/2019-01767

Vulnerable Software (320)

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: red hat enterprise linux 7.0

Trait:
{  "version_end_including": "8.5.33",  "version_start_including": "8.5.0"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: red hat enterprise linux 7.0

Trait:
{  "version_end_including": "7.0.90",  "version_start_including": "7.0.23"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: red hat enterprise linux 7.0

Trait:
{  "version_end_including": "9.0.11",  "version_start_including": "9.0.0.M1"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: red hat enterprise linux 8.0

Trait:
{  "version_end_including": "8.5.33",  "version_start_including": "8.5.0"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: red hat enterprise linux 8.0

Trait:
{  "version_end_including": "7.0.90",  "version_start_including": "7.0.23"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: red hat enterprise linux 8.0

Trait:
{  "version_end_including": "9.0.11",  "version_start_including": "9.0.0.M1"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: opensuse leap 15.1

Trait:
{  "version_end_including": "8.5.33",  "version_start_including": "8.5.0"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: opensuse leap 15.1

Trait:
{  "version_end_including": "7.0.90",  "version_start_including": "7.0.23"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: opensuse leap 15.1

Trait:
{  "version_end_including": "9.0.11",  "version_start_including": "9.0.0.M1"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: debian gnu/linux 8

Trait:
{  "version_end_including": "8.5.33",  "version_start_including": "8.5.0"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: debian gnu/linux 8

Trait:
{  "version_end_including": "7.0.90",  "version_start_including": "7.0.23"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: debian gnu/linux 8

Trait:
{  "version_end_including": "9.0.11",  "version_start_including": "9.0.0.M1"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: ubuntu 14.04 LTS

Trait:
{  "version_end_including": "8.5.33",  "version_start_including": "8.5.0"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: ubuntu 14.04 LTS

Trait:
{  "version_end_including": "7.0.90",  "version_start_including": "7.0.23"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: ubuntu 14.04 LTS

Trait:
{  "version_end_including": "9.0.11",  "version_start_including": "9.0.0.M1"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: ubuntu 16.04 LTS

Trait:
{  "version_end_including": "8.5.33",  "version_start_including": "8.5.0"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: ubuntu 16.04 LTS

Trait:
{  "version_end_including": "7.0.90",  "version_start_including": "7.0.23"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: ubuntu 16.04 LTS

Trait:
{  "version_end_including": "9.0.11",  "version_start_including": "9.0.0.M1"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: fedora 28

Trait:
{  "version_end_including": "8.5.33",  "version_start_including": "8.5.0"}

Source: bdu

Type: Configuration

Vendor: apache software foundation

Product: tomcat

Operating System: fedora 28

Trait:
{  "version_end_including": "7.0.90",  "version_start_including": "7.0.23"}

Source: bdu