Cross-site scripting in Apache Tomcat - CVE-2024-52318

 

Cross-site scripting in Apache Tomcat - CVE-2024-52318

Published: November 18, 2024


Vulnerability identifier: #VU100591
CSH Severity: Medium
CVSS v4 BT: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Green]
CVE-ID: CVE-2024-52318
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data in generated JSPs. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

Apache Tomcat
EasyApache
IBM UrbanCode Release
IBM Rational Build Forge
IBM Power Hardware Management Console (HMC)
NetWorker
UCD - IBM UrbanCode Deploy
Traffix SDC
DevOps
IBM QRadar Incident Forensics
DevOps Deploy
openEuler
Fedora
IBM Qradar SIEM
tomcat-jsvc
tomcat
tomcat-help
IBM Security SOAR

How to mitigate CVE-2024-52318

Install updates from vendor's website.

Apache Tomcat - addressed in versions 9.0.97, 10.1.33, 11.0.1
EasyApache - update to 4 2024-11-20
DevOps - update to 7.0.0.4
IBM Rational Build Forge - update to 8.0.0.28
IBM Power Hardware Management Console (HMC) - addressed in versions 10.2.1040.0 SP3, 10.3.1060.0 SP1
NetWorker - update to 19.13.0.1
UCD - IBM UrbanCode Deploy - addressed in versions 7.0.5.26, 7.1.2.22, 7.2.3.15, 7.3.2.10
IBM QRadar Incident Forensics - update to 7.5.0 UP10 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF02
DevOps Deploy - addressed in versions 8.0.1.5, 8.1.0.1
tomcat-jsvc - update to 9.0.96-2
tomcat - update to 9.0.96-2
tomcat-help - update to 9.0.96-2
tomcat - addressed in versions 9.0.97-1.fc40, 9.0.97-1.fc41, 9.0.97-1.fc42, 9.0.98-1.fc40, 9.0.98-1.fc41
IBM Security SOAR - update to 51.0.4.1

External References

Related Security Bulletins