Korean
<< Back
VID 22944
Severity 30
Port 80, ...
Protocol TCP
Class WWW
Detailed Description The version of Tomcat installed on the remote host is prior to 8.5.56. It is, therefore, affected by a vulnerability as referenced in the fixed_in_apache_tomcat_8.5.56_security-8 advisory. Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

* References:
https://github.com/apache/tomcat/commit/c8acd2ab7371e39aeca7c306f3b5380f00afe552
https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.56

* Platforms Affected:
Apache Tomcat Server versions 8.5.x prior to 8.5.56
Any operating system Any version
Recommendation Upgrade to the latest version of Apache Tomcat Server (8.5.56 or later), available from the Apache Software Foundation download site, http://tomcat.apache.org/
Related URL CVE-2020-11996 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)