This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Summuary
CPE Namecpe:/a:apache:tomcat:5.5.20
Detail
VendorApacheFirst view 2007-03-16
ProductTomcatLast view 2012-11-30
Version5.5.20TypeApplication
Edition 
Language 
Update 
 
CPE Productcpe:/a:apache:tomcat

Activity : Yearly

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
 DateAlertAccess VectorAccess ComplexityAuthentification
52012-11-30CVE-2012-5568NetworkLowNone Requ...
52012-11-17CVE-2012-5887NetworkLowNone Requ...
52012-11-17CVE-2012-5886NetworkLowNone Requ...
52012-11-17CVE-2012-5885NetworkLowNone Requ...
52012-01-18CVE-2012-0022NetworkLowNone Requ...
Hide | Show 20 More...
 DateAlertAccess VectorAccess ComplexityAuthentification
4.32012-01-14CVE-2011-5064NetworkMediumNone Requ...
4.32012-01-14CVE-2011-5063NetworkMediumNone Requ...
52012-01-14CVE-2011-5062NetworkLowNone Requ...
52012-01-14CVE-2011-1184NetworkLowNone Requ...
7.52011-08-31CVE-2011-3190NetworkLowNone Requ...
4.42011-07-14CVE-2011-2526LocalMediumNone Requ...
1.92011-06-29CVE-2011-2204LocalMediumNone Requ...
4.32011-02-18CVE-2011-0013NetworkMediumNone Requ...
1.22011-02-10CVE-2010-3718LocalHighNone Requ...
6.42010-07-13CVE-2010-2227NetworkLowNone Requ...
2.62010-04-23CVE-2010-1157NetworkHighNone Requ...
4.32010-01-28CVE-2009-2902NetworkMediumNone Requ...
4.32010-01-28CVE-2009-2901NetworkMediumNone Requ...
5.82010-01-28CVE-2009-2693NetworkMediumNone Requ...
7.52009-11-12CVE-2009-3548NetworkLowNone Requ...
52009-06-16CVE-2008-5515NetworkLowNone Requ...
4.62009-06-05CVE-2009-0783LocalLowNone Requ...
4.32009-06-05CVE-2009-0580NetworkMediumNone Requ...
52009-06-05CVE-2009-0033NetworkLowNone Requ...

CWE : Common Weakness Enumeration

%idName
24% (9)CWE-200Information Exposure
16% (6)CWE-264Permissions, Privileges, and Access Controls
16% (6)CWE-79Failure to Preserve Web Page Structure ('Cross-site Scripting')
13% (5)CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path ...
8% (3)CWE-287Improper Authentication
Hide | Show 6 More...
%idName
5% (2)CWE-20Improper Input Validation
5% (2)CWE-16Configuration
2% (1)CWE-310Cryptographic Issues
2% (1)CWE-255Credentials Management
2% (1)CWE-189Numeric Errors
2% (1)CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer

CAPEC : Common Attack Pattern Enumeration & Classificatio

idName
CAPEC-102Session Sidejacking

Oval Markup Language : Definitions

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
OvalIDName
oval:org.mitre.oval:def:10643Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before...
oval:org.mitre.oval:def:10578Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in t...
oval:org.mitre.oval:def:11287Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2...
oval:org.mitre.oval:def:11269Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1...
oval:org.mitre.oval:def:9549Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1...
Hide | Show 20 More...
idName
oval:org.mitre.oval:def:10077Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apac...
oval:org.mitre.oval:def:11177Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4...
oval:org.mitre.oval:def:10417The default catalina.policy in the JULI logging component in Apache Tomcat 5....
oval:org.mitre.oval:def:5985Security vulnerability in the HttpServletResponse.sendError method in Tomcat ...
oval:org.mitre.oval:def:11181Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.3...
oval:org.mitre.oval:def:6009Security vulnerability in the Virtual Host Manager in Tomcat 5.5 bundled with...
oval:org.mitre.oval:def:11534Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.2...
oval:org.mitre.oval:def:5876Security vulnerability in the RequestDispatcher class in Tomcat 5.5 bundled w...
oval:org.mitre.oval:def:10577Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6...
oval:org.mitre.oval:def:6445HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthor...
oval:org.mitre.oval:def:10422Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.1...
oval:org.mitre.oval:def:5739HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthor...
oval:org.mitre.oval:def:10231Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6...
oval:org.mitre.oval:def:9101Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6...
oval:org.mitre.oval:def:6628HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthor...
oval:org.mitre.oval:def:6564HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthor...
oval:org.mitre.oval:def:11041Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar ...
oval:org.mitre.oval:def:6450HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthor...
oval:org.mitre.oval:def:10716Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6...
oval:org.mitre.oval:def:7017HP-UX Running Tomcat Servlet Engine, Remote Increase in Privilege, Arbitrary ...

Open Source Vulnerability Database (OSVDB)

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
idDescription
78573Apache Tomcat CPU Consumption Parameter Saturation Remote DoS
76189Apache Tomcat HTTP DIGEST Authentication Weakness
74818Apache Tomcat AJP Message Injection Authentication Bypass
73798Apache Tomcat sendfile Request Start / Endpoint Parsing Local DoS
73797Apache Tomcat sendfile Request Attribute Validation Weakness Local Access Res...
Hide | Show 20 More...
idDescription
73429Apache Tomcat JMX MemoryUserDatabase Local Password Disclosure
71558Apache Tomcat SecurityManager ServletContext Attribute Traversal Arbitrary Fi...
71557Apache Tomcat HTML Manager Multiple XSS
66319Apache Tomcat Crafted Transfer-Encoding Header Handling Buffer Recycling Remo...
64023Apache Tomcat WWW-Authenticate Header Local Host Information Disclosure
62511CA Service Desk Tomcat host-manager/html/add name Parameter XSS
62054Apache Tomcat WAR Filename Traversal Work-directory File Deletion
62053Apache Tomcat Autodeployment Process appBase File HTTP Request Authentication...
62052Apache Tomcat WAR File Traversal Arbitrary File Overwrite
60176Apache Tomcat Windows Installer Admin Default Password
55056Apache Tomcat Cross-application TLD File Manipulation
55055Apache Tomcat Illegally URL Encoded Password Request Username Enumeration
55054Apache Tomcat Java AJP Connector mod_jk Load Balancing Worker Malformed Heade...
55053Apache Tomcat Crafted Request Security Restraint Bypass Arbitrary Content Access
53381Apache Tomcat JK Connector Content-Length Header Cross-user Information Discl...
52899Apache Tomcat Examples Web Application Calendar Application jsp/cal/cal2.jsp ...
52407Apache Tomcat doRead Method POST Content Information Disclosure
47463Apache Tomcat RequestDispatcher Traversal Arbitrary File Access
47462Apache Tomcat HttpServletResponse.sendError Method Message Argument XSS
45905Apache Tomcat Host Manager host-manager/html/add name Parameter XSS

ExploitDB Exploits

idDescription
12343Apache Tomcat v. 5.5.0 to 5.5.29 & 6.0.0 to 6.0.26 information disclosure vul...

Metasploit Exploits

idDescription
2010-07-09Apache Tomcat Transfer-Encoding Information Disclosure and DoS
2009-11-09Apache Tomcat Manager Application Deployer Authenticated Code Execution