Apache.Tomcat.Form.Authentication.Example.XSS
Description
This indicates an attack attempt to exploit a Cross-Site Scripting Vulnerability in Apache Tomcat.
This vulnerability is due to improper input validation of the Form authentication example page. A remote, authenticated attacker could exploit this vulnerability by submitting a crafted request to the target server. Successful exploitation could result in arbitrary code execution in the context of the victim's browser.
Affected Products
Apache Tomcat 10.1.0-M1 to 10.1.0-M16
Apache Tomcat 10.0.0-M1 to 10.0.22
Apache Tomcat 9.0.30 to 9.0.64
Apache Tomcat 8.5.50 to 8.5.81
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://tomcat.apache.org/security-10.html https://tomcat.apache.org/security-9.html https://tomcat.apache.org/security-8.html
Version Updates
Date | Version | Detail |
---|---|---|
2022-10-19 | 0.00331 |