CVE-2018-1304 Details
Description
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache tomcat | >= 7.0.0, <= 7.0.84 >= 8.0.0, <= 8.0.49 >= 8.5.0, <= 8.5.27 >= 9.0.0, <= 9.0.4 8.0.0 rc1 9.0.0 milestone1 9.0.0 milestone10 9.0.0 milestone11 9.0.0 milestone12 9.0.0 milestone13 9.0.0 milestone14 9.0.0 milestone15 9.0.0 milestone16 9.0.0 milestone17 9.0.0 milestone18 9.0.0 milestone19 9.0.0 milestone2 9.0.0 milestone20 9.0.0 milestone21 9.0.0 milestone22 9.0.0 milestone23 9.0.0 milestone24 9.0.0 milestone25 9.0.0 milestone26 9.0.0 milestone27 9.0.0 milestone3 9.0.0 milestone4 9.0.0 milestone5 9.0.0 milestone6 9.0.0 milestone7 9.0.0 milestone8 9.0.0 milestone9 |
CPE
Remediation
| |
| redhat jboss enterprise application platform | 6 6.4 |
CPE
Remediation
| |
| redhat jboss enterprise web server | 3.0.0 |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 |
CPE
Remediation
| |
| debian debian linux | 7.0 8.0 9.0 |
CPE
Remediation
| |
| canonical ubuntu linux | 14.04 16.04 17.10 18.04 |
CPE
Remediation
| |
| oracle fusion middleware | 12.2.1.3.0 |
CPE
Remediation
| |
| oracle hospitality guest access | 4.2.0 4.2.1 |
CPE
Remediation
| |
| oracle micros relate crm software | 11.4 |
CPE
Remediation
| |
| oracle secure global desktop | 5.3 5.4 |
CPE
Remediation
| |
| redhat jboss middleware | 1 |
CPE
Remediation
| |
Change History
59 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Apr 15, 2020 | CVE Modified | [email protected] |
| Feb 13, 2020 | CVE Modified | [email protected] |
| Feb 3, 2020 | CVE Modified | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Aug 6, 2019 | CVE Modified | [email protected] |
| Jul 23, 2019 | CVE Modified | [email protected] |
| May 10, 2019 | Modified Analysis | [email protected] |
| Apr 23, 2019 | CVE Modified | [email protected] |
| Apr 22, 2019 | CPE Deprecation Remap | [email protected] |
| Apr 15, 2019 | CVE Modified | [email protected] |
| Apr 15, 2019 | CVE Modified | [email protected] |
| Apr 3, 2019 | Modified Analysis | [email protected] |
| Mar 25, 2019 | CVE Modified | [email protected] |
| Mar 21, 2019 | CVE Modified | [email protected] |
| Oct 18, 2018 | CVE Modified | [email protected] |
| Oct 17, 2018 | CVE Modified | [email protected] |
| Aug 29, 2018 | CVE Modified | [email protected] |
| Jul 31, 2018 | CVE Modified | [email protected] |
| Jul 19, 2018 | CVE Modified | [email protected] |
| Jul 8, 2018 | CVE Modified | [email protected] |
| Jun 29, 2018 | CVE Modified | [email protected] |
| Jun 1, 2018 | CVE Modified | [email protected] |
| May 17, 2018 | CVE Modified | [email protected] |
| May 5, 2018 | CVE Modified | [email protected] |
| Mar 26, 2018 | Initial Analysis | [email protected] |
| Mar 9, 2018 | CVE Modified | [email protected] |
| Mar 8, 2018 | CVE Modified | [email protected] |
| Mar 2, 2018 | CVE Modified | [email protected] |