CVE-2018-11784 is an open redirect vulnerability affecting Apache Tomcat versions 7.0.23-7.0.90, 8.5.0-8.5.33, and 9.0.0.M1-9.0.11. An attacker can craft a malicious URL that, when processed by Tomcat's default servlet during a directory redirect, forces the user's browser to an arbitrary URI of the attacker's choosing. This medium severity vulnerability (CVSS 4.3) requires user interaction and primarily impacts integrity, as it can be used for phishing or other social engineering attacks. While not listed on CISA's KEV catalog or the Hot List, public exploit code exists, including Nuclei templates and an ExploitDB entry, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0.23, <= 7.0.90CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 8.5.0, <= 8.5.33CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 9.0.1, <= 9.0.11CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
9.0.0CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:9.0.0:*:*:*:*:*:*:* | ||
9.0.0CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:9.0.0:milestone1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.