Lucene search

K
cvelistApacheCVELIST:CVE-2017-7675
HistoryAug 11, 2017 - 2:00 a.m.

CVE-2017-7675

2017-08-1102:00:00
apache
www.cve.org
7

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

54.9%

The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. It was therefore possible to bypass security constraints using a specially crafted URL.

CNA Affected

[
  {
    "product": "Apache Tomcat",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "9.0.0.M1 to 9.0.0.M21"
      },
      {
        "status": "affected",
        "version": "8.5.0 to 8.5.15"
      }
    ]
  }
]

References

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

54.9%