CVE-2016-0762
- EPSS 0.97%
- Veröffentlicht 10.08.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a timing attac...
CVE-2016-5018
- EPSS 1.31%
- Veröffentlicht 10.08.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applica...
CVE-2016-6794
- EPSS 0.49%
- Veröffentlicht 10.08.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the ...
CVE-2017-10243
- EPSS 0.95%
- Veröffentlicht 08.08.2017 15:29:07
- Zuletzt bearbeitet 20.04.2025 01:37:25
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAX-WS). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulne...
CVE-2017-10176
- EPSS 1.77%
- Veröffentlicht 08.08.2017 15:29:05
- Zuletzt bearbeitet 20.04.2025 01:37:25
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerabil...
CVE-2017-10193
- EPSS 0.49%
- Veröffentlicht 08.08.2017 15:29:05
- Zuletzt bearbeitet 20.04.2025 01:37:25
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Difficult to exploit vulnerability allows unauthen...
CVE-2017-10198
- EPSS 0.34%
- Veröffentlicht 08.08.2017 15:29:05
- Zuletzt bearbeitet 20.04.2025 01:37:25
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Difficult to exploit v...
CVE-2017-10125
- EPSS 0.17%
- Veröffentlicht 08.08.2017 15:29:04
- Zuletzt bearbeitet 20.04.2025 01:37:25
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 7u141 and 8u131. Difficult to exploit vulnerability allows physical access to compromise Java SE. While the vulnera...
CVE-2017-10135
- EPSS 0.41%
- Veröffentlicht 08.08.2017 15:29:04
- Zuletzt bearbeitet 20.04.2025 01:37:25
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Difficult to exploit vulner...
CVE-2017-10096
- EPSS 0.47%
- Veröffentlicht 08.08.2017 15:29:03
- Zuletzt bearbeitet 20.04.2025 01:37:25
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticate...