Lucene search

K
f5F5F5:K9109
HistoryMar 19, 2013 - 12:00 a.m.

K9109 : Apache Tomcat cross-site scripting vulnerability CVE-2008-1947

2013-03-1900:00:00
my.f5.com
20

6.9 Medium

AI Score

Confidence

High

0.1 Low

EPSS

Percentile

94.9%

Security Advisory Description

Note: Versions that are not listed in this article have not been evaluated for vulnerability to this security advisory. For information about the F5 security policy regarding evaluating older and unsupported versions of F5 products, refer to K4602: Overview of the F5 security vulnerability response policy.

F5 products and versions that have been evaluated for this Security Advisory

Product Affected Not Affected
BIG-IP LTM None 9.x
10.x
11.x
BIG-IP GTM None 9.x
10.x
11.x
BIG-IP ASM None 9.x
10.x
11.x
BIG-IP Link Controller None 9.x
10.x
11.x

BIG-IP WebAccelerator| None| 9.x
10.x
11.x
BIG-IP PSM| None| 9.x
10.x
11.x
BIG-IP WAN Optimization| None| 10.x
11.x
BIG-IP APM| None| 10.x
11.x
BIG-IP Edge Gateway| None| 10.x
11.x
BIG-IP Analytics| None| 11.x
BIG-IP AFM| None| 11.x
BIG-IP PEM
| None| 11.x
FirePass| None| 5.x
6.x
7.x
Enterprise Manager| None| 1.x
2.x
3.x
ARX| None| 2.x
3.x
4.x
5.x

Vulnerability description and product information

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML through the name parameter (the hostname attribute) to host-manager/html/add.

Information about this advisory is available at the following location:

<https://vulners.com/cve/CVE-2008-1947&gt;