Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38806
HistoryJan 09, 2023 - 6:49 p.m.

Arbitrary Code Injection

2023-01-0918:49:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
46
tomcat
catalina
arbitrary code injection
jsonerrorreportvalve
vulnerability
improper escaping
inputs

0.005 Low

EPSS

Percentile

75.9%

Tomcat Catalina is vulnerable to Arbitrary Code Injection. The vulnerability exists in the report function of JsonErrorReportValve.java due to improper escaping of inputs from JsonErrorReportValve which allows an attacker to inject invalid input values.