First published: Fri Feb 23 2018(Updated: )
Apache Tomcat versions 7.0.0 to 7.0.84, 8.0.0.RC1 to 8.0.49 and 8.5.0 to 8.5.27 does not properly handle the URL empty string ("") when used as part of a security constraint definition. This can lead to the security constraint being ignored, leading to unitended exposure of resources. External References: <a href="https://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.85">https://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.85</a> <a href="https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.0.50">https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.0.50</a> <a href="https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.28">https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.28</a> Upstream Bug Report: <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=62067">https://bz.apache.org/bugzilla/show_bug.cgi?id=62067</a> Upstream Fixes: Tomcat 7.0.x: <a href="http://svn.apache.org/viewvc?view=rev&rev=1823309">http://svn.apache.org/viewvc?view=rev&rev=1823309</a> Tomcat 8.0.x: <a href="http://svn.apache.org/viewvc?view=rev&rev=1814827">http://svn.apache.org/viewvc?view=rev&rev=1814827</a> Tomcat 8.5.x: <a href="http://svn.apache.org/viewvc?view=rev&rev=1823307">http://svn.apache.org/viewvc?view=rev&rev=1823307</a>
Credit: security@apache.org security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Tomcat | >=7.0.0<=7.0.84 | |
Apache Tomcat | >=8.0.0<=8.0.49 | |
Apache Tomcat | >=8.5.0<=8.5.27 | |
Apache Tomcat | >=9.0.0<=9.0.4 | |
Apache Tomcat | =8.0.0-rc1 | |
Apache Tomcat | =9.0.0-m1 | |
Apache Tomcat | =9.0.0-m10 | |
Apache Tomcat | =9.0.0-m11 | |
Apache Tomcat | =9.0.0-m12 | |
Apache Tomcat | =9.0.0-m13 | |
Apache Tomcat | =9.0.0-m14 | |
Apache Tomcat | =9.0.0-m15 | |
Apache Tomcat | =9.0.0-m16 | |
Apache Tomcat | =9.0.0-m17 | |
Apache Tomcat | =9.0.0-m18 | |
Apache Tomcat | =9.0.0-m19 | |
Apache Tomcat | =9.0.0-m2 | |
Apache Tomcat | =9.0.0-m20 | |
Apache Tomcat | =9.0.0-m21 | |
Apache Tomcat | =9.0.0-m22 | |
Apache Tomcat | =9.0.0-m23 | |
Apache Tomcat | =9.0.0-m24 | |
Apache Tomcat | =9.0.0-m25 | |
Apache Tomcat | =9.0.0-m26 | |
Apache Tomcat | =9.0.0-m27 | |
Apache Tomcat | =9.0.0-m3 | |
Apache Tomcat | =9.0.0-m4 | |
Apache Tomcat | =9.0.0-m5 | |
Apache Tomcat | =9.0.0-m6 | |
Apache Tomcat | =9.0.0-m7 | |
Apache Tomcat | =9.0.0-m8 | |
Apache Tomcat | =9.0.0-m9 | |
Redhat Jboss Enterprise Application Platform | =6 | |
Redhat Jboss Enterprise Application Platform | =6.4 | |
Redhat Jboss Enterprise Web Server | =3.0.0 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
Canonical Ubuntu Linux | =18.04 | |
Oracle Fusion Middleware | =12.2.1.3.0 | |
Oracle Hospitality Guest Access | =4.2.0 | |
Oracle Hospitality Guest Access | =4.2.1 | |
Oracle Micros Relate Crm Software | =11.4 | |
Oracle Secure Global Desktop | =5.3 | |
Oracle Secure Global Desktop | =5.4 | |
Redhat Jboss Middleware | =1 | |
Apache Tomcat | =9.0.0-milestone1 | |
Apache Tomcat | =9.0.0-milestone10 | |
Apache Tomcat | =9.0.0-milestone11 | |
Apache Tomcat | =9.0.0-milestone12 | |
Apache Tomcat | =9.0.0-milestone13 | |
Apache Tomcat | =9.0.0-milestone14 | |
Apache Tomcat | =9.0.0-milestone15 | |
Apache Tomcat | =9.0.0-milestone16 | |
Apache Tomcat | =9.0.0-milestone17 | |
Apache Tomcat | =9.0.0-milestone18 | |
Apache Tomcat | =9.0.0-milestone19 | |
Apache Tomcat | =9.0.0-milestone2 | |
Apache Tomcat | =9.0.0-milestone20 | |
Apache Tomcat | =9.0.0-milestone21 | |
Apache Tomcat | =9.0.0-milestone22 | |
Apache Tomcat | =9.0.0-milestone23 | |
Apache Tomcat | =9.0.0-milestone24 | |
Apache Tomcat | =9.0.0-milestone25 | |
Apache Tomcat | =9.0.0-milestone26 | |
Apache Tomcat | =9.0.0-milestone27 | |
Apache Tomcat | =9.0.0-milestone3 | |
Apache Tomcat | =9.0.0-milestone4 | |
Apache Tomcat | =9.0.0-milestone5 | |
Apache Tomcat | =9.0.0-milestone6 | |
Apache Tomcat | =9.0.0-milestone7 | |
Apache Tomcat | =9.0.0-milestone8 | |
Apache Tomcat | =9.0.0-milestone9 | |
All of | ||
Any of | ||
Redhat Jboss Enterprise Application Platform | =6 | |
Redhat Jboss Enterprise Application Platform | =6.4 | |
Redhat Jboss Enterprise Web Server | =3.0.0 | |
Any of | ||
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
redhat/tomcat | <7.0.85 | 7.0.85 |
redhat/tomcat | <8.0.50 | 8.0.50 |
redhat/tomcat | <8.5.28 | 8.5.28 |
maven/org.apache.tomcat.embed:tomcat-embed-core | >=7.0.0<7.0.86 | 7.0.86 |
maven/org.apache.tomcat.embed:tomcat-embed-core | >=8.0.0<8.0.51 | 8.0.51 |
maven/org.apache.tomcat.embed:tomcat-embed-core | >=8.5.0<8.5.28 | 8.5.28 |
maven/org.apache.tomcat.embed:tomcat-embed-core | >=9.0.0<=9.0.4 | 9.0.5 |
debian/tomcat9 | 9.0.43-2~deb11u10 9.0.70-2 9.0.95-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.