Lucene search

K
kasperskyKaspersky LabKLA50474
HistoryMay 19, 2023 - 12:00 a.m.

KLA50474 OSI vulnerability in Apache Tomcat

2023-05-1900:00:00
Kaspersky Lab
threats.kaspersky.com
20
apache tomcat
vulnerability
information disclosure
update
osi
cve-2023-34981

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.4

Confidence

High

EPSS

0.003

Percentile

69.0%

An information disclosure vulnerability was found in Apache Tomcat. Malicious users can exploit this vulnerability to obtain sensitive information.

Original advisories

Fixed in Apache Tomcat 10.1.9

Fixed in Apache Tomcat 8.5.89

Related products

Apache-Tomcat

CVE list

CVE-2023-34981 critical

Solution

Update to the latest versionTomcat 10.1 Software Downloads

Tomcat 8.5 Software Downloads

Impacts

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

Affected Products

  • Apache Tomcat 8.5.x earlier than 8.5.89Apache Tomcat 10.1.x earlier than 10.1.9

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.4

Confidence

High

EPSS

0.003

Percentile

69.0%