CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
AI Score
Confidence
High
EPSS
Percentile
85.5%
It was discovered that the Tomcat SecurityManager did not properly restrict
the working directory. An attacker could use this flaw to read or write
files outside of the intended working directory. (CVE-2010-3718)
It was discovered that Tomcat did not properly escape certain parameters in
the Manager application which could result in browsers becoming vulnerable
to cross-site scripting attacks when processing the output. With cross-site
scripting vulnerabilities, if a user were tricked into viewing server
output during a crafted server request, a remote attacker could exploit
this to modify the contents, or steal confidential data (such as
passwords), within the same domain. (CVE-2011-0013)
It was discovered that Tomcat incorrectly enforced the maxHttpHeaderSize
limit in certain configurations. A remote attacker could use this flaw to
cause Tomcat to consume all available memory, resulting in a denial of
service. (CVE-2011-0534)
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Ubuntu | 9.10 | noarch | libtomcat6-java | < 6.0.20-2ubuntu2.4 | UNKNOWN |
Ubuntu | 9.10 | noarch | libservlet2.5-java | < 6.0.20-2ubuntu2.4 | UNKNOWN |
Ubuntu | 9.10 | noarch | libservlet2.5-java-doc | < 6.0.20-2ubuntu2.4 | UNKNOWN |
Ubuntu | 9.10 | noarch | tomcat6 | < 6.0.20-2ubuntu2.4 | UNKNOWN |
Ubuntu | 9.10 | noarch | tomcat6-admin | < 6.0.20-2ubuntu2.4 | UNKNOWN |
Ubuntu | 9.10 | noarch | tomcat6-common | < 6.0.20-2ubuntu2.4 | UNKNOWN |
Ubuntu | 9.10 | noarch | tomcat6-docs | < 6.0.20-2ubuntu2.4 | UNKNOWN |
Ubuntu | 9.10 | noarch | tomcat6-examples | < 6.0.20-2ubuntu2.4 | UNKNOWN |
Ubuntu | 9.10 | noarch | tomcat6-user | < 6.0.20-2ubuntu2.4 | UNKNOWN |
Ubuntu | 10.10 | noarch | libtomcat6-java | < 6.0.28-2ubuntu1.2 | UNKNOWN |