Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web script or HTML via the test parameter and unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 4.1.37Upgrade Apache Tomcat to 5.0.0Upgrade Apache Tomcat to 5.5.24Upgrade Apache Tomcat to 6.0.11 | May 17, 2012 | May 21, 2007 |
| Apple Osx Tomcat | — | Apply OS X security update 2008-004 | Dec 16, 2011 | May 21, 2007 |
| Freebsd | — | Upgrade tomcatUpgrade jakarta-tomcatUpgrade apache-tomcat | Dec 10, 2025 | Jul 24, 2007 |
| Hpux | — | Update hpuxwsAPACHE to the latest version | Aug 11, 2017 | May 21, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub