Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 8.0.0Upgrade Apache Tomcat to 6.0.39Upgrade Apache Tomcat to 7.0.50 | Mar 3, 2014 | Feb 26, 2014 |
| Centos_linux | — | Upgrade tomcat6-javadocUpgrade tomcat6-libUpgrade tomcat6-docs-webappUpgrade tomcat6-admin-webappsUpgrade tomcat6-servlet-2.5-apiUpgrade tomcat6-webappsUpgrade tomcat6-jsp-2.1-apiUpgrade tomcat6Upgrade tomcat6-el-2.1-api | Dec 1, 2016 | Feb 26, 2014 |
| Debian | — | Upgrade tomcat6 | Mar 28, 2016 | Feb 26, 2014 |
| Gentoo Linux | — | Upgrade www-servers/tomcat. | Oct 30, 2017 | Feb 26, 2014 |
| Oracle Solaris | — | Upgrade web/java-servlet/tomcat/tomcat-examples to version 6.0.39-0.175.1.19.0.2.0 on Solaris 11.1Upgrade web/java-servlet/tomcat to version 6.0.39-0.175.1.19.0.2.0 on Solaris 11.1 | May 29, 2017 | Feb 26, 2014 |
| Oracle_linux | — | Upgrade tomcat6-servlet-2.5-apiUpgrade tomcat6-docs-webappUpgrade tomcat6-javadocUpgrade tomcat6-webappsUpgrade tomcat6-admin-webappsUpgrade tomcat6-el-2.1-apiUpgrade tomcat6Upgrade tomcat6-libUpgrade tomcat6-jsp-2.1-api | Oct 16, 2024 | Feb 26, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 25, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub