Apache Tomcat
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*, +1 more
- >= 11.0.0-M1, <= 11.0.10
- >= 10.1.0-M1, <= 10.1.44
- >= 9.0.40, <= 9.0.108
- ~8.5
A vulnerability exists in Apache Tomcat versions 11.0.0-M1 through 11.0.10, 10.1.0-M1 through 10.1.44, and 9.0.40 through 9.0.108, as well as older, end-of-life versions. The issue arises from Tomcat's failure to properly escape ANSI escape sequences in log messages. When running in a console on Windows that supports these sequences, an attacker could inject escape sequences through a crafted URL. This injection could manipulate the console and clipboard, potentially tricking an administrator into executing a command controlled by the attacker.
Exploitation could lead to unauthorized manipulation of the console and clipboard, with the possibility of tricking an administrator into executing an attacker-controlled command.
Users are advised to upgrade to Apache Tomcat 11.0.11 or later, 10.1.45 or later, or 9.0.109 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.