Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.813736
Category:Web Servers
Title:Apache TomEE console (tomee-webapp) XSS Vulnerability
Summary:Apache TomEE is prone to a cross-site scripting (XSS) vulnerability.
Description:Summary:
Apache TomEE is prone to a cross-site scripting (XSS) vulnerability.

Vulnerability Insight:
The flaw exists due to an unspecified error in
the 'tomee-webapp' web application which is typically used to add TomEE features
to a Tomcat installation.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to conduct Cross Site Scripting attacks.

Affected Software/OS:
Apache TomEE console (tomee-webapp)

Solution:
Removing the application after TomEE is setup
(if using the application to install TomEE) or use one of the provided
pre-configured installation bundles or upgrade to TomEE 7.0.5.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-8031
https://lists.apache.org/thread.html/c4b0d83a534d6cdf2de54dbbd00e3538072ac2e360781b784608ed0d@%3Cdev.tomee.apache.org%3E
CopyrightCopyright (C) 2018 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.