Korean
<< Back
VID 22803
Severity 30
Port 80, ...
Protocol TCP
Class WWW
Detailed Description The version of Apache Tomcat installed on the remote host is 8.0.0.RC1 or later but prior to 8.0.45. It is, therefore, affected by a flaw in the CORS filter where the HTTP Vary header is not properly added. This allows a remote attacker to conduct client-side and server-side cache poisoning attacks.

* References:
http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.0.45

* Platforms Affected:
Apache Tomcat Server versions 8.0.x prior to 8.0.45
Any operating system Any version
Recommendation Upgrade to the latest version of Apache Tomcat Server (8.0.45 or later), available from the Apache Software Foundation download site, http://tomcat.apache.org/
Related URL CVE-2017-7674 (CVE)
Related URL 100280 (SecurityFocus)
Related URL (ISS)