CVE-2018-1304: Apache Tomcat
Medium severity, CVSS 5.9. EPSS: 17.1% chance of exploitation in the next 30 days.
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.
Affected products
- Apache Tomcat: from 7.0.0, up to and including 7.0.84; from 8.0.0, up to and including 8.0.49; from 8.5.0, up to and including 8.5.27; from 9.0.0, up to and including 9.0.4; version 8.0.0 only; version 9.0.0 only
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.10 only; version 18.04 only
- Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
- Oracle Fusion Middleware: version 12.2.1.3.0 only
- Oracle Hospitality Guest Access: version 4.2.0 only; version 4.2.1 only
- Oracle Micros Relate CRM Software: version 11.4 only
- Oracle Secure Global Desktop: version 5.3 only; version 5.4 only
- Red Hat JBoss Enterprise Application Platform: version 6 only; version 6.4 only
- Red Hat JBoss Enterprise Web Server: version 3.0.0 only
- Red Hat JBoss Middleware: version 1 only
Published 2018-02-28. Last modified 2026-06-17.