CVE-2018-11784: Apache Tomcat

Medium severity, CVSS 4.3. EPSS: 97.7% chance of exploitation in the next 30 days.

When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.

Affected products

  • Apache Tomcat: from 7.0.23, up to and including 7.0.90; from 8.5.0, up to and including 8.5.33; from 9.0.1, up to and including 9.0.11; version 9.0.0 only
  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only
  • Debian Debian Linux: version 8.0 only
  • Netapp Snap Creator Framework: affected versions not specified
  • Oracle Communications Application Session Controller: version 3.7.1 only; version 3.8.0 only
  • Oracle Hospitality Guest Access: version 4.2.0 only; version 4.2.1 only
  • Oracle Instantis Enterprisetrack: version 17.1 only; version 17.2 only; version 17.3 only
  • Oracle Retail Order Broker: version 5.1 only; version 5.2 only; version 15.0 only
  • Oracle Secure Global Desktop: version 5.4 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only; version 7.6 only
  • Red Hat Enterprise Linux Server Aus: version 7.6 only
  • Red Hat Enterprise Linux Server Eus: version 7.6 only
  • Red Hat Enterprise Linux Server Tus: version 7.6 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2018-10-04. Last modified 2026-06-17.