QID 995375
Date Published: 2023-09-25
QID 995375: Java (Maven) Security Update for org.apache.tomcat:tomcat (GHSA-hc39-rjwp-qffq)
Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the ; character, as demonstrated by a URI containing a snp/snoop.jsp; sequence.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-hc39-rjwp-qffq for updates and patch information.
Vendor References
- GHSA-hc39-rjwp-qffq -
github.com/advisories/GHSA-hc39-rjwp-qffq
CVEs related to QID 995375
Software Advisories
| Advisory ID | Software | Component | Link |
|---|