Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7772
HistoryNov 13, 2018 - 6:36 a.m.

Cross-site Scripting (XSS)

2018-11-1306:36:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.718 High

EPSS

Percentile

98.1%

tomcat-http is vulnerable to cross-site scripting (XSS) attacks. The vulnerability exists due to the assumption that the Accept-Language header value received conforms to RFC 2616, allowing XSS attacks.

References