Apache.Tomcat.Form.Authentication.Example.XSS

description-logoDescription

This indicates an attack attempt to exploit a Cross-Site Scripting Vulnerability in Apache Tomcat.
This vulnerability is due to improper input validation of the Form authentication example page. A remote, authenticated attacker could exploit this vulnerability by submitting a crafted request to the target server. Successful exploitation could result in arbitrary code execution in the context of the victim's browser.

affected-products-logoAffected Products

Apache Tomcat 10.1.0-M1 to 10.1.0-M16
Apache Tomcat 10.0.0-M1 to 10.0.22
Apache Tomcat 9.0.30 to 9.0.64
Apache Tomcat 8.5.50 to 8.5.81

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

Version Updates

Date Version Detail
2022-10-19 0.00331

CVE References

CVE-2022-34305