As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify which script to execute. The update was not correct. As a result, some scripts may have failed to execute as expected and other scripts may have been executed unexpectedly. Note that the behaviour of the CGI servlet has remained unchanged in this regard. It is only the documentation of the behaviour that was wrong and has been corrected.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade tomcat7Upgrade tomcat80Upgrade tomcat8 | Feb 9, 2018 | Jan 31, 2018 |
| Apache Tomcat | — | Upgrade Apache Tomcat to 8.5.24Upgrade Apache Tomcat to 7.0.84Upgrade Apache Tomcat to 8.0.48Upgrade Apache Tomcat to 9.0.2Upgrade Apache Tomcat to the latest available version | Feb 1, 2018 | Jan 31, 2018 |
| Oracle Solaris | — | Upgrade web/java-servlet/tomcat-8/tomcat-admin to version 8.5.28-0.175.3.31.0.1.0 on Solaris 11.3Upgrade web/java-servlet/tomcat-8 to version 8.5.28-0.175.3.31.0.1.0 on Solaris 11.3Upgrade web/java-servlet/tomcat-8/tomcat-examples to version 8.5.28-0.175.3.31.0.1.0 on Solaris 11.3 | Apr 18, 2018 | Jan 31, 2018 |
| Suse | — | Upgrade tomcat-admin-webappsUpgrade tomcat-servlet-3_1-apiUpgrade tomcat-jsp-2_2-apiUpgrade tomcat-el-2_2-apiUpgrade tomcat-webappsUpgrade tomcat-javadocUpgrade tomcat-servlet-4_0-apiUpgrade tomcat-libUpgrade tomcat-jsp-2_3-apiUpgrade tomcat-servlet-3_0-apiUpgrade tomcat-el-3_0-apiUpgrade tomcatUpgrade tomcat-docs-webapp | Mar 27, 2018 | Jan 31, 2018 |
| Ubuntu | — | Upgrade tomcat8Upgrade libtomcat8-javaUpgrade tomcat7Upgrade libtomcat7-java | Jun 8, 2018 | Jan 31, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub