4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
0.968 High
EPSS
Percentile
99.7%
Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in
the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0
through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0
through 6.0.13 allow remote attackers to inject arbitrary web script or
HTML via the portion of the URI after the ‘;’ character, as demonstrated by
a URI containing a “snp/snoop.jsp;” sequence.