CVE-2011-0013

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Affected Products (NVD)
VendorProductVersion
apachetomcat
7.0.0
apachetomcat
7.0.1
apachetomcat
7.0.2
apachetomcat
7.0.3
apachetomcat
7.0.4
apachetomcat
7.0.5
apachetomcat
6.0
apachetomcat
6.0.0
apachetomcat
6.0.1
apachetomcat
6.0.2
apachetomcat
6.0.3
apachetomcat
6.0.4
apachetomcat
6.0.5
apachetomcat
6.0.6
apachetomcat
6.0.7
apachetomcat
6.0.8
apachetomcat
6.0.9
apachetomcat
6.0.10
apachetomcat
6.0.11
apachetomcat
6.0.12
apachetomcat
6.0.13
apachetomcat
6.0.14
apachetomcat
6.0.15
apachetomcat
6.0.16
apachetomcat
6.0.17
apachetomcat
6.0.18
apachetomcat
6.0.19
apachetomcat
6.0.20
apachetomcat
6.0.24
apachetomcat
6.0.26
apachetomcat
6.0.27
apachetomcat
6.0.28
apachetomcat
6.0.29
apachetomcat
5.5.0
apachetomcat
5.5.1
apachetomcat
5.5.2
apachetomcat
5.5.3
apachetomcat
5.5.4
apachetomcat
5.5.5
apachetomcat
5.5.6
apachetomcat
5.5.7
apachetomcat
5.5.8
apachetomcat
5.5.9
apachetomcat
5.5.10
apachetomcat
5.5.11
apachetomcat
5.5.12
apachetomcat
5.5.13
apachetomcat
5.5.14
apachetomcat
5.5.15
apachetomcat
5.5.16
apachetomcat
5.5.17
apachetomcat
5.5.18
apachetomcat
5.5.19
apachetomcat
5.5.20
apachetomcat
5.5.21
apachetomcat
5.5.22
apachetomcat
5.5.23
apachetomcat
5.5.24
apachetomcat
5.5.25
apachetomcat
5.5.26
apachetomcat
5.5.27
apachetomcat
5.5.28
apachetomcat
5.5.29
apachetomcat
5.5.30
apachetomcat
5.5.31
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tomcat5
dapper
ignored
hardy
dne
karmic
dne
lucid
dne
maverick
dne
natty
dne
tomcat5.5
dapper
dne
hardy
ignored
karmic
dne
lucid
dne
maverick
dne
natty
dne
tomcat6
dapper
dne
hardy
dne
karmic
Fixed 6.0.20-2ubuntu2.4
released
lucid
Fixed 6.0.24-2ubuntu1.7
released
maverick
Fixed 6.0.28-2ubuntu1.2
released
natty
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
tomcat6
RHEL 6
0:6.0.24-33.el6
fixed
tomcat6-admin-webapps
RHEL 6
0:6.0.24-33.el6
fixed
tomcat6-docs-webapp
RHEL 6
0:6.0.24-33.el6
fixed
tomcat6-el-2.1-api
RHEL 6
0:6.0.24-33.el6
fixed
tomcat6-javadoc
RHEL 6
0:6.0.24-33.el6
fixed
tomcat6-jsp-2.1-api
RHEL 6
0:6.0.24-33.el6
fixed
tomcat6-lib
RHEL 6
0:6.0.24-33.el6
fixed
tomcat6-servlet-2.5-api
RHEL 6
0:6.0.24-33.el6
fixed
tomcat6-webapps
RHEL 6
0:6.0.24-33.el6
fixed
References