Apache Tomcat
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*, +1 more
- >= 11.0.0-M1, <= 11.0.7
- >= 10.1.0, <= 10.1.41
- >= 9.0.23, <= 9.0.105
A side-loading vulnerability has been identified in the Apache Tomcat installer for Windows. This issue arises from the installer using icacls.exe without a specified full path, creating an untrusted search path vulnerability. Affected versions include Apache Tomcat 11.0.0-M1 through 11.0.7, 10.1.0 through 10.1.41, and 9.0.23 through 9.0.105.
Exploitation of this vulnerability could lead to unauthorized side-loading of libraries, potentially allowing for the execution of malicious code.
Users are advised to upgrade to Apache Tomcat 11.0.8, 10.1.42, or 9.0.106.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.