Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-8014


The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.


Published

2018-05-16T16:29:00.207

Last Modified

2024-11-21T04:13:05.810

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-1188

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache tomcat ≤ 7.0.88 Yes
Application apache tomcat ≤ 8.0.52 Yes
Application apache tomcat ≤ 8.5.31 Yes
Application apache tomcat ≤ 9.0.8 Yes
Application apache tomcat 8.0.0 Yes
Application apache tomcat 9.0.0 Yes
Operating System canonical ubuntu_linux 14.04 Yes
Operating System canonical ubuntu_linux 16.04 Yes
Operating System canonical ubuntu_linux 17.10 Yes
Operating System canonical ubuntu_linux 18.04 Yes
Operating System debian debian_linux 8.0 Yes
Application netapp oncommand_insight - Yes
Application netapp oncommand_unified_manager ≥ 9.4 Yes
Application netapp oncommand_workflow_automation - Yes
Application netapp snapcenter_server - Yes
Application netapp storage_automation_store - Yes
Application netapp oncommand_unified_manager ≥ 7.3 Yes
Operating System microsoft windows - No

References