Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to 6.0.30Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 7.0.5 | May 17, 2012 | Nov 26, 2010 |
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2011-006 | Aug 28, 2015 | Nov 26, 2010 |
| Apple Osx Tomcat | — | Apply OS X security update 2011-006 | Dec 16, 2011 | Nov 26, 2010 |
| Gentoo Linux | — | Upgrade www-servers/tomcat. | Oct 30, 2017 | Nov 26, 2010 |
| Oracle_linux | — | Upgrade tomcat6-jsp-2.1-apiUpgrade tomcat6-docs-webappUpgrade tomcat6-admin-webappsUpgrade tomcat6-webappsUpgrade tomcat6-libUpgrade tomcat6-servlet-2.5-apiUpgrade tomcat6-javadocUpgrade tomcat6-el-2.1-apiUpgrade tomcat6 | Oct 16, 2024 | Nov 26, 2010 |
| Suse | — | Upgrade tomcat6-admin-webappsUpgrade tomcat6-servlet-2_5-apiUpgrade tomcat6Upgrade tomcat6-libUpgrade tomcat6-webappsUpgrade tomcat6-javadocUpgrade tomcat6-docs-webappUpgrade tomcat6-jsp-2_1-api | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade tomcat6-admin | Nov 8, 2024 | Nov 26, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub