← Back

CVE-2013-4590

nvd nist
Published: Feb 26, 2014Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Affected (193)

1 product
Tomcat
1 product
Debian Linux
1 product
Solaris
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 8.0.0 rc1
Version 8.0.0 rc2
Version 8.0.0 rc3
Version 8.0.0 rc4
Version 8.0.0 rc5
Version 8.0.0 rc6
Version 8.0.0 rc7
Version 8.0.0 rc8
Version 8.0.0 rc9
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0
Configuration C
136 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Up to 6.0.37
Version 1.1.3
Version 3.0
Version 3.1.1
Version 3.1
Version 3.2.1
Version 3.2.2
Version 3.2.2 beta2
Version 3.2.3
Version 3.2.4
Version 3.2
Version 3.3.1
Version 3.3.1a
Version 3.3.2
Version 3.3
Version 4.0.0
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.0.5
Version 4.0.6
Version 4.1.0
Version 4.1.10
Version 4.1.12
Version 4.1.15
Version 4.1.1
Version 4.1.24
Version 4.1.28
Version 4.1.29
Version 4.1.2
Version 4.1.31
Version 4.1.36
Version 4.1.3
Version 4.1.3 beta
Version 4.1.9 beta
Version 4
Version 5.0.0
Version 5.0.10
Version 5.0.11
Version 5.0.12
Version 5.0.13
Version 5.0.14
Version 5.0.15
Version 5.0.16
Version 5.0.17
Version 5.0.18
Version 5.0.19
Version 5.0.1
Version 5.0.21
Version 5.0.22
Version 5.0.23
Version 5.0.24
Version 5.0.25
Version 5.0.26
Version 5.0.27
Version 5.0.28
Version 5.0.29
Version 5.0.2
Version 5.0.30
Version 5.0.3
Version 5.0.4
Version 5.0.5
Version 5.0.6
Version 5.0.7
Version 5.0.8
Version 5.0.9
Version 5.5.0
Version 5.5.10
Version 5.5.11
Version 5.5.12
Version 5.5.13
Version 5.5.14
Version 5.5.15
Version 5.5.16
Version 5.5.17
Version 5.5.18
Version 5.5.19
Version 5.5.1
Version 5.5.20
Version 5.5.21
Version 5.5.22
Version 5.5.23
Version 5.5.24
Version 5.5.25
Version 5.5.26
Version 5.5.27
Version 5.5.28
Version 5.5.29
Version 5.5.2
Version 5.5.30
Version 5.5.31
Version 5.5.32
Version 5.5.33
Version 5.5.34
Version 5.5.35
Version 5.5.3
Version 5.5.4
Version 5.5.5
Version 5.5.6
Version 5.5.7
Version 5.5.8
Version 5.5.9
Version 5
Version 6.0.0
Version 6.0.0 alpha
Version 6.0.10
Version 6.0.11
Version 6.0.12
Version 6.0.13
Version 6.0.14
Version 6.0.15
Version 6.0.16
Version 6.0.17
Version 6.0.18
Version 6.0.19
Version 6.0.1
Version 6.0.1 alpha
Version 6.0.20
Version 6.0.24
Version 6.0.26
Version 6.0.27
Version 6.0.28
Version 6.0.29
Version 6.0.2
Version 6.0.2 alpha
Version 6.0.2 beta
Version 6.0.30
Version 6.0.31
Version 6.0.32
Version 6.0.33
Version 6.0.35
Version 6.0.36
Version 6.0.3
Version 6.0
Version 6
Configuration D
46 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 7.0.0
Version 7.0.0 beta
Version 7.0.10
Version 7.0.11
Version 7.0.12
Version 7.0.13
Version 7.0.14
Version 7.0.15
Version 7.0.16
Version 7.0.17
Version 7.0.18
Version 7.0.19
Version 7.0.1
Version 7.0.20
Version 7.0.21
Version 7.0.22
Version 7.0.23
Version 7.0.24
Version 7.0.25
Version 7.0.26
Version 7.0.27
Version 7.0.28
Version 7.0.29
Version 7.0.2
Version 7.0.2 beta
Version 7.0.30
Version 7.0.31
Version 7.0.32
Version 7.0.33
Version 7.0.34
Version 7.0.35
Version 7.0.36
Version 7.0.37
Version 7.0.38
Version 7.0.39
Version 7.0.3
Version 7.0.40
Version 7.0.41
Version 7.0.42
Version 7.0.43
Version 7.0.44
Version 7.0.45
Version 7.0.46
Version 7.0.4
Version 7.0.4 beta
Version 7.0.50
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.2

References (62)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Mailing List
Source: secalert@redhat.com
Permissions RequiredThird Party Advisory
Source: secalert@redhat.com
Permissions RequiredThird Party Advisory
Source: secalert@redhat.com
Permissions RequiredThird Party Advisory
Source: secalert@redhat.com
Permissions RequiredThird Party Advisory
Source: secalert@redhat.com
Issue Tracking
Source: secalert@redhat.com
Issue Tracking
Source: secalert@redhat.com
Issue Tracking
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking

Timeline

No history available yet.