imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2002-2009
Medium 5.0

Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %20/, which leaks the pathname in an error message.

apache tomcat
0.07EPSS
CVE-2008-5519
Low 2.6

The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from a different client that includ…

apache mod_jk · apache tomcat
0.07EPSS
CVE-2005-3351
Medium 5.0

SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.

apache spamassassin
0.07EPSS
CVE-2011-2729
Medium 5.0

native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attac…

apache apache_commons_daemon · apache tomcat
0.07EPSS
CVE-2019-12420
High 7.5

In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly.

apache spamassassin · debian debian_linux
0.07EPSS
CVE-2023-37924
Critical 9.8

Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can result in unauthorized login. Now we have fixed this issue and now user must have the correct login to access workbench. This issue affects Apach…

apache submarine
0.07EPSS
CVE-2020-11982
Critical 9.8

An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious payload directly to the broker which could lead to a deserializ…

apache airflow
0.07EPSS
CVE-2013-2185
High 7.5

The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in…

apache tomcat · redhat jboss_enterprise_application_platform · redhat jboss_enterprise_portal_platform
0.07EPSS
CVE-2017-12634
Critical 9.8

The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.

apache camel
0.07EPSS
CVE-2016-6817
High 7.5

The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possible.

apache tomcat
0.07EPSS
CVE-2021-41079
High 7.5

Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loo…

apache tomcat · debian debian_linux · netapp management_services_for_element_software_and_netapp_hci
0.07EPSS
CVE-2014-3612
High 7.5

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unau…

apache activemq
0.07EPSS
CVE-2016-8747
High 7.5

An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request.

apache tomcat · netapp oncommand_insight · netapp oncommand_shift
0.07EPSS
CVE-2014-3584
Medium 5.0

The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service.

apache cxf
0.07EPSS
CVE-2018-8040
Medium 5.3

Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This affects Apache Traffic Server (ATS) versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x sh…

apache traffic_server · debian debian_linux
0.07EPSS
CVE-2016-6794
Medium 5.3

When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system pro…

apache tomcat · canonical ubuntu_linux · debian debian_linux · netapp oncommand_insight · and 10 more
0.07EPSS
CVE-2024-32114
High 8.5

In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are located). It means that anyone can use these layers without any required authentication. Potentially, anyone can i…

apache activemq
0.07EPSS
CVE-2013-2067
Medium 6.8

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which all…

apache tomcat
0.07EPSS
CVE-2020-28052
High 8.1

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed …

apache karaf · bouncycastle bc-java · oracle banking_corporate_lending_process_management · oracle banking_credit_facilities_process_management · and 16 more
0.07EPSS
CVE-2007-5731
Low 3.5

Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag, a related issue to CVE-2007-5461.

apache jakarta_slide
0.07EPSS
CVE-2017-12633
Critical 9.8

The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.

apache camel
0.07EPSS
CVE-2015-5344
Critical 9.8

The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.

apache camel
0.07EPSS
CVE-2002-2008
Medium 5.0

Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the information in an error message.

apache tomcat
0.07EPSS
CVE-2016-0783
High 7.5

The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attackers to reset arbitrary user passwords by leveraging knowledge of a user name and the current system time.

apache openmeetings
0.07EPSS
CVE-2015-0264
Medium 5.0

Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile obj…

apache camel
0.07EPSS