Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13001
HistoryJan 15, 2019 - 9:24 a.m.

Insecure Defaults

2019-01-1509:24:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

EPSS

0.055

Percentile

93.3%

Apache Tomcat is vulnerable to insecure defaults. The CORS filter provided by default is insecure as it enables supportsCredentials for all origins. This can allow a malicious user unauthorized access to sensitive resources.

References