| Title | Apache Tomcat におけるアクセス制御に関する脆弱性 |
|---|---|
| Summary | Apache Tomcat には、アクセス制御に関する脆弱性が存在します。 |
| Possible impacts | 情報を取得される、および情報を改ざんされる可能性があります。 |
| Solution | 参考情報を参照して適切な対策を実施してください。 |
| Publication Date | April 11, 2017, midnight |
| Registration Date | May 15, 2017, 6:17 p.m. |
| Last Update | Oct. 3, 2017, 1:42 p.m. |
| CVSS3.0 : 緊急 | |
| Score | 9.1 |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| CVSS2.0 : 警告 | |
| Score | 6.4 |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
| Apache Software Foundation |
| Apache Tomcat 7.0.0 から 7.0.75 |
| Apache Tomcat 8.0.0.RC1 から 8.0.41 |
| Apache Tomcat 8.5.0 から 8.5.11 |
| Apache Tomcat 9.0.0.M1 から 9.0.0.M17 |
| 日本電気 |
| MailShooter |
| SimpWright |
| SpoolServer/Winspoolシリーズ |
| WebOTX Application Server Enterprise |
| WebOTX Application Server Express |
| WebOTX Application Server Standard |
| WebOTX Developer |
| WebOTX Portal |
| WebSAM Application Navigator 4.2.0.1 以降 |
| WebSAM MCOperations 4.2.1.0 以降 |
| WebSAM SystemManager 6.2.1.0 以降 |
| No | Changed Details | Date of change |
|---|---|---|
| 0 | [2017年05月15日] 掲載 [2017年07月25日] 影響を受けるシステム:ベンダ情報の追加に伴い内容を更新 ベンダ情報:日本電気 (NV17-012) を追加 [2017年10月03日] 影響を受けるシステム:ベンダ情報 (NV17-012) の更新に伴い内容を更新 |
Feb. 17, 2018, 10:37 a.m. |
| Summary | While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application. |
|---|---|
| Publication Date | April 18, 2017, 1:59 a.m. |
| Registration Date | Jan. 26, 2021, 1:26 p.m. |
| Last Update | Nov. 21, 2024, 12:28 p.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:apache:tomcat:7.0.49:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.12:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.62:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.53:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.20:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.34:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.58:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.8:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.55:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.51:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.63:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.22:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.39:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.26:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.46:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.72:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.71:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.28:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.59:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.65:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.50:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.18:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.14:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.48:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.11:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.67:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.74:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.23:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.66:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.44:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.69:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.52:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.42:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.60:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.37:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.29:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.45:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.68:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.13:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.47:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.41:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.31:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.30:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.15:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.19:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.75:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.16:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.10:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.36:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.25:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.54:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.35:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.61:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.57:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.43:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.32:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.38:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.21:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.27:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.24:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.17:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.40:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.9:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.56:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.64:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.70:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.33:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:7.0.73:*:*:*:*:*:*:* | |||||
| Configuration2 | or higher | or less | more than | less than | |
| cpe:2.3:a:apache:tomcat:8.0.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.10:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.30:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.17:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.26:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.40:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.20:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.31:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.19:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.39:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.12:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.27:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.15:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.0:rc1:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.22:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.29:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.11:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.24:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.36:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.23:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.33:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.21:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.32:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.41:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.25:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.18:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.35:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.38:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.13:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.14:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.9:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.16:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.8:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.34:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.28:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.0.37:*:*:*:*:*:*:* | |||||
| Configuration3 | or higher | or less | more than | less than | |
| cpe:2.3:a:apache:tomcat:8.5.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.5.9:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.5.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.5.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.5.10:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.5.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.5.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.5.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.5.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.5.8:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.5.11:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:8.5.1:*:*:*:*:*:*:* | |||||
| Configuration4 | or higher | or less | more than | less than | |
| cpe:2.3:a:apache:tomcat:9.0.0:milestone1:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:9.0.0:milestone10:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:9.0.0:milestone11:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:9.0.0:milestone12:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:9.0.0:milestone13:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:9.0.0:milestone14:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:9.0.0:milestone15:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:9.0.0:milestone16:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:9.0.0:milestone17:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:9.0.0:milestone2:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:9.0.0:milestone3:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:9.0.0:milestone4:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:9.0.0:milestone5:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:9.0.0:milestone6:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:9.0.0:milestone7:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:9.0.0:milestone8:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:tomcat:9.0.0:milestone9:*:*:*:*:*:* | |||||