CVE-2020-1938
- EPSS 99.27%
- Veröffentlicht 24.02.2020 22:15:12
- Zuletzt bearbeitet 27.10.2025 17:37:12
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available t...
CVE-2019-17569
- EPSS 8.87%
- Veröffentlicht 24.02.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:33
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of H...
CVE-2019-10219
- EPSS 2.17%
- Veröffentlicht 08.11.2019 15:15:11
- Zuletzt bearbeitet 07.07.2025 14:15:21
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
CVE-2019-10086
- EPSS 29.95%
- Veröffentlicht 20.08.2019 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:22
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by defa...
CVE-2019-2725
- EPSS 99.96%
- Veröffentlicht 26.04.2019 19:29:00
- Zuletzt bearbeitet 12.08.2026 05:17:26
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with ...
CVE-2018-15756
- EPSS 9.51%
- Veröffentlicht 18.10.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:51:24
Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler,...
CVE-2018-11039
- EPSS 2.78%
- Veröffentlicht 25.06.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:32
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring ...
CVE-2018-1258
- EPSS 2.46%
- Veröffentlicht 11.05.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:28
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted...
CVE-2017-12617
- EPSS 99.99%
- Veröffentlicht 04.10.2017 01:29:02
- Zuletzt bearbeitet 21.04.2026 17:03:52
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload ...
CVE-2017-10039
- EPSS 1.62%
- Veröffentlicht 08.08.2017 15:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Web Client). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network a...