← All CVEs

CVE-2017-7675

high · 7.5

The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. It was therefore possible to bypass security constraints using a specially crafted URL.

7.5
CVSS
10.1%
EPSS (exploit prob.)
95th
EPSS percentile
2017-08-11
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
apachetomcat8.5.0
apachetomcat8.5.1
apachetomcat8.5.2
apachetomcat8.5.3
apachetomcat8.5.4
apachetomcat8.5.5
apachetomcat8.5.6
apachetomcat8.5.7
apachetomcat8.5.8
apachetomcat8.5.9
apachetomcat8.5.10
apachetomcat8.5.11
apachetomcat8.5.12
apachetomcat8.5.13
apachetomcat8.5.14
apachetomcat8.5.15
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-7675