[Forgot Password]
Login  Register Subscribe

24128

 
 

131573

 
 

111017

 
 

909

 
 

86402

 
 

136

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2017-7674Date: (C)2017-08-15   (M)2018-07-03


The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 4.3CVSS Score : 4.3
Exploit Score: 2.8Exploit Score: 8.6
Impact Score: 1.4Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: REQUIREDConfidentiality: NONE
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: NONEAvailability: NONE
Integrity: LOW 
Availability: NONE 
  
Reference:
BID-100280
DSA-3974
RHSA-2017:1801
RHSA-2017:1802
RHSA-2017:3081
https://lists.apache.org/thread.html/22b4bb077502f847e2b9fcf00b96e81e734466ab459780ff73b60c0f@%3Cannounce.tomcat.apache.org%3E
https://lists.debian.org/debian-lts-announce/2018/06/msg00008.html
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
https://security.netapp.com/advisory/ntap-20180614-0003/
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03828en_us

CPE    113
cpe:/a:apache:tomcat:8.0
cpe:/a:apache:tomcat:7.0.71
cpe:/a:apache:tomcat:7.0.70
cpe:/a:apache:tomcat:7.0.62
...
CWE    1
CWE-345
OVAL    6
oval:org.secpod.oval:def:113146
oval:org.secpod.oval:def:113143
oval:org.secpod.oval:def:1600778
oval:org.secpod.oval:def:204699
...

© SecPod Technologies