CRITICALMaven →
Insufficiently Protected Credentials in Apache Tomcat
Insufficiently Protected Credentials in Apache Tomcat
Affected packages
- org.apache.tomcat.embed:tomcat-embed-core— before 7.0.99
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://nvd.nist.gov/vuln/detail/CVE-2019-12418
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.debian.org/security/2020/dsa-4680
- https://www.debian.org/security/2019/dsa-4596
- https://usn.ubuntu.com/4251-1
- https://support.f5.com/csp/article/K10107360?utm_source=f5support&utm_medium=RSS
- https://security.netapp.com/advisory/ntap-20200107-0001
- https://security.gentoo.org/glsa/202003-43
- https://seclists.org/bugtraq/2019/Dec/43
- https://lists.debian.org/debian-lts-announce/2020/03/msg00029.html
- https://lists.debian.org/debian-lts-announce/2020/01/msg00024.html
- https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/43530b91506e2e0c11cfbe691173f5df8c48f51b98262426d7493b67%40%3Cannounce.tomcat.apache.org%3E
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00013.html
Structured record: https://osv.dev/vulnerability/GHSA-hh3j-x4mc-g48r
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta