<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:04:48 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-01045</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-01045</link>
      <description>bdu:2023-01045</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-01045</guid>
    </item>
    <item>
      <title>certfr-2017-avi-332 — Une vulnérabilité a été découverte dans Apache Tomcat. Elle permet à un
attaquant de provoquer une exécution de code ar…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2017-avi-332</link>
      <description>certfr-2017-avi-332</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2017-avi-332</guid>
    </item>
    <item>
      <title>cnvd-2017-30092</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-30092</link>
      <description>cnvd-2017-30092</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-30092</guid>
    </item>
    <item>
      <title>EUVD-2026-256307</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-256307</link>
      <description>EUVD-2026-256307</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-256307</guid>
    </item>
    <item>
      <title>fkie_cve-2017-12617</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-12617</link>
      <description>&lt;p&gt;When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-12617</guid>
    </item>
    <item>
      <title>GHSA-xjgh-84hx-56c5 — Unrestricted Upload of File with Dangerous Type Apache Tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xjgh-84hx-56c5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat-catalina, Maven: org.apache.tomcat.embed:tomcat-embed-core&lt;/p&gt;
&lt;p&gt;When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat-catalina, Maven: org.apache.tomcat.embed:tomcat-embed-core&lt;/p&gt;
&lt;p&gt;When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xjgh-84hx-56c5</guid>
    </item>
    <item>
      <title>gsd-2017-12617</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-12617</link>
      <description>gsd-2017-12617</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-12617</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11468-1 — tomcat-9.0.36-8.4 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11468-1</link>
      <description>&lt;p&gt;tomcat-9.0.36-8.4 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat-9.0.36-8.4 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11468-1</guid>
    </item>
    <item>
      <title>RHSA-2017:3080 — Red Hat Security Advisory: tomcat6 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2017:3080</link>
      <description>&lt;p&gt;tomcat: Incorrect handling of pipelined requests when send file was used tomcat: Security constrained bypass in error page mechanism tomcat: Remote Code Execution via JSP Upload tomcat: Remote Code Execution bypass for CVE-2017-12615&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat: Incorrect handling of pipelined requests when send file was used tomcat: Security constrained bypass in error page mechanism tomcat: Remote Code Execution via JSP Upload tomcat: Remote Code Execution bypass for CVE-2017-12615&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2017:3080</guid>
    </item>
    <item>
      <title>SUSE-SU-2017:3039-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2017:3039-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2017:3039-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2017-12617</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-12617</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:Pro:18.04:LTS: tomcat7&lt;/p&gt;
&lt;p&gt;When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:Pro:18.04:LTS: tomcat7&lt;/p&gt;
&lt;p&gt;When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-12617</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0528 — Dell Data Protection Advisor: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0528</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen, seine Berechtigungen zu erweitern oder einen nicht spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen, seine Berechtigungen zu erweitern oder einen nicht spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0528</guid>
    </item>
  </channel>
</rss>
