Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7868
HistoryNov 21, 2018 - 6:37 a.m.

Remote Code Execution (RCE)

2018-11-2106:37:28
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
23

EPSS

0.001

Percentile

17.9%

catalina is vulnerable to a remote code execution (RCE) attack. The library allows the replacement of the XML parser used for other web applications, allowing a malicious user to gain access to the applications’ web.xml, context.xml or tld files.

References