MEDIUM · 5.9

CVE-2018-1304

The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 w...

Vulnerability Description

The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.

CVSS Score

5.9

MEDIUM

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
ApacheTomcat>= 7.0.0, <= 7.0.84
RedhatJboss Enterprise Application Platform6
RedhatJboss Enterprise Web Server3.0.0
RedhatEnterprise Linux6.0
DebianDebian Linux7.0
CanonicalUbuntu Linux14.04
OracleFusion Middleware12.2.1.3.0
OracleHospitality Guest Access4.2.0
OracleMicros Relate Crm Software11.4
OracleSecure Global Desktop5.3
RedhatJboss Middleware1

References

FAQ

What is CVE-2018-1304?

CVE-2018-1304 is a vulnerability with a CVSS score of 5.9 (MEDIUM). The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 w...

How severe is CVE-2018-1304?

CVE-2018-1304 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-1304?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat, Redhat Jboss Enterprise Application Platform, Redhat Jboss Enterprise Web Server, Redhat Enterprise Linux, Debian Debian Linux.