Apache Tomcat - (bulletinoct2018)ID: oval:org.secpod.oval:def:2103427 | Date: (C)2020-01-07 (M)2023-12-14 |
Class: PATCH | Family: unix |
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to "/foo/" when the user requested "/foo") a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.
Product: |
web/java-servlet/tomcat-8 |
web/java-servlet/tomcat-8/tomcat-examples |
web/java-servlet/tomcat-8/tomcat-admin |