Lucene search

K
f5F5F5:K92665308
HistoryAug 17, 2017 - 12:00 a.m.

K92665308 : Apache Tomcat vulnerabilities CVE-2017-7674 and CVE-2017-7675

2017-08-1700:00:00
my.f5.com
37

5.9 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.4%

Security Advisory Description

The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances.

The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. It was therefore possible to bypass security constraints using a specially crafted URL.

Impact

There is no impact; F5 products are not affected by this vulnerability.