CVE-2018-11784: Apache Tomcat
Medium severity, CVSS 4.3. EPSS: 97.7% chance of exploitation in the next 30 days.
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.
Affected products
- Apache Tomcat: from 7.0.23, up to and including 7.0.90; from 8.5.0, up to and including 8.5.33; from 9.0.1, up to and including 9.0.11; version 9.0.0 only
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only
- Debian Debian Linux: version 8.0 only
- Netapp Snap Creator Framework: affected versions not specified
- Oracle Communications Application Session Controller: version 3.7.1 only; version 3.8.0 only
- Oracle Hospitality Guest Access: version 4.2.0 only; version 4.2.1 only
- Oracle Instantis Enterprisetrack: version 17.1 only; version 17.2 only; version 17.3 only
- Oracle Retail Order Broker: version 5.1 only; version 5.2 only; version 15.0 only
- Oracle Secure Global Desktop: version 5.4 only
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only; version 7.6 only
- Red Hat Enterprise Linux Server Aus: version 7.6 only
- Red Hat Enterprise Linux Server Eus: version 7.6 only
- Red Hat Enterprise Linux Server Tus: version 7.6 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
Published 2018-10-04. Last modified 2026-06-17.