Lucene search

K
osvGoogleOSV:GHSA-P57V-P3FX-QGWM
HistoryMay 01, 2022 - 7:45 a.m.

Apache Tomcat XSS Vulnerability

2022-05-0107:45:38
Google
osv.dev
11
apache
tomcat
xss
vulnerability
remote attackers
web script
html
header values

AI Score

5.7

Confidence

High

EPSS

0.016

Percentile

87.6%

Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.

References

AI Score

5.7

Confidence

High

EPSS

0.016

Percentile

87.6%