CVE Database
/

CVE-2013-4590

Back to search

CVE-2013-4590

Published: Feb 26, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

VendorProductVersions

n/a

n/a

affected
n/a

References

MDVSA-2015:052
vendor-advisory
x_refsource_MANDRIVA
59724
third-party-advisory
x_refsource_SECUNIA
MDVSA-2015:084
vendor-advisory
x_refsource_MANDRIVA
DSA-3530
vendor-advisory
x_refsource_DEBIAN
59722
third-party-advisory
x_refsource_SECUNIA
65768
vdb-entry
x_refsource_BID
59873
third-party-advisory
x_refsource_SECUNIA
HPSBOV03503
vendor-advisory
x_refsource_HP
59036
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now