<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:05:00 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-01759</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-01759</link>
      <description>bdu:2019-01759</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-01759</guid>
    </item>
    <item>
      <title>cnvd-2018-03661</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-03661</link>
      <description>cnvd-2018-03661</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-03661</guid>
    </item>
    <item>
      <title>EUVD-2026-180227</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-180227</link>
      <description>EUVD-2026-180227</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-180227</guid>
    </item>
    <item>
      <title>fkie_cve-2018-1304</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-1304</link>
      <description>&lt;p&gt;The URL pattern of &amp;#34;&amp;#34; (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The URL pattern of &amp;#34;&amp;#34; (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-1304</guid>
    </item>
    <item>
      <title>GHSA-6rxj-58jh-436r — Apache Tomcat unauthorized access vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6rxj-58jh-436r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat.embed:tomcat-embed-core&lt;/p&gt;
&lt;p&gt;The URL pattern of &amp;#34;&amp;#34; (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat.embed:tomcat-embed-core&lt;/p&gt;
&lt;p&gt;The URL pattern of &amp;#34;&amp;#34; (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6rxj-58jh-436r</guid>
    </item>
    <item>
      <title>gsd-2018-1304</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-1304</link>
      <description>gsd-2018-1304</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-1304</guid>
    </item>
    <item>
      <title>RHSA-2018:0465 — Red Hat Security Advisory: Red Hat JBoss Web Server 3.1.0 Service Pack 2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:0465</link>
      <description>&lt;p&gt;apr: Out-of-bounds array deref in apr_time_exp*() functions tomcat: Remote Code Execution via JSP Upload tomcat: Information Disclosure when using VirtualDirContext tomcat: Remote Code Execution bypass for CVE-2017-12615 tomcat-native: Mishandling of client certificates can allow for OCSP check bypass tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources tomcat: Late application of security constraints can lead to resource exposure for unauthorised users&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apr: Out-of-bounds array deref in apr_time_exp*() functions tomcat: Remote Code Execution via JSP Upload tomcat: Information Disclosure when using VirtualDirContext tomcat: Remote Code Execution bypass for CVE-2017-12615 tomcat-native: Mishandling of client certificates can allow for OCSP check bypass tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources tomcat: Late application of security constraints can lead to resource exposure for unauthorised users&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:0465</guid>
    </item>
    <item>
      <title>RHSA-2019:2205 — Red Hat Security Advisory: tomcat security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2019:2205</link>
      <description>&lt;p&gt;tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources tomcat: Late application of security constraints can lead to resource exposure for unauthorised users tomcat: Insecure defaults in CORS filter enable &amp;#39;supportsCredentials&amp;#39; for all origins tomcat: Host name verification missing in WebSocket client&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources tomcat: Late application of security constraints can lead to resource exposure for unauthorised users tomcat: Insecure defaults in CORS filter enable &amp;#39;supportsCredentials&amp;#39; for all origins tomcat: Host name verification missing in WebSocket client&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2019:2205</guid>
    </item>
    <item>
      <title>SUSE-SU-2018:0817-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2018:0817-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2018:0817-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-1304</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1304</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7&lt;/p&gt;
&lt;p&gt;The URL pattern of &amp;#34;&amp;#34; (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7&lt;/p&gt;
&lt;p&gt;The URL pattern of &amp;#34;&amp;#34; (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1304</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0528 — Dell Data Protection Advisor: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0528</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen, seine Berechtigungen zu erweitern oder einen nicht spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen, seine Berechtigungen zu erweitern oder einen nicht spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0528</guid>
    </item>
  </channel>
</rss>
