CVE-2018-1305: Apache Tomcat

Medium severity, CVSS 6.5. EPSS: 14.5% chance of exploitation in the next 30 days.

Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were loaded - for some security constraints not to be applied. This could have exposed resources to users who were not authorised to access them.

Affected products

  • Apache Tomcat: from 7.0.0, up to and including 7.0.84; from 8.0.0, up to and including 8.0.49; version 8.0.0 only; version 9.0.0 only; version 9.0.1 only; version 9.0.2 only; …
  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.10 only; version 18.04 only
  • Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
  • Oracle Fusion Middleware: version 12.2.1.3.0 only
  • Oracle Managed File Transfer: version 12.1.3.0.0 only; version 12.2.1.3.0 only
  • Oracle Micros Relate CRM Software: version 11.4 only

Published 2018-02-23. Last modified 2026-06-17.