Cross-site scripting in Apache Tomcat - CVE-2024-52318
Published: November 18, 2024
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in generated JSPs. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
EasyApache
IBM UrbanCode Release
IBM Rational Build Forge
IBM Power Hardware Management Console (HMC)
NetWorker
UCD - IBM UrbanCode Deploy
Traffix SDC
DevOps
IBM QRadar Incident Forensics
DevOps Deploy
openEuler
Fedora
IBM Qradar SIEM
tomcat-jsvc
tomcat
tomcat-help
IBM Security SOAR
How to mitigate CVE-2024-52318
EasyApache - update to 4 2024-11-20
DevOps - update to 7.0.0.4
IBM Rational Build Forge - update to 8.0.0.28
IBM Power Hardware Management Console (HMC) - addressed in versions 10.2.1040.0 SP3, 10.3.1060.0 SP1
NetWorker - update to 19.13.0.1
UCD - IBM UrbanCode Deploy - addressed in versions 7.0.5.26, 7.1.2.22, 7.2.3.15, 7.3.2.10
IBM QRadar Incident Forensics - update to 7.5.0 UP10 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF02
DevOps Deploy - addressed in versions 8.0.1.5, 8.1.0.1
tomcat-jsvc - update to 9.0.96-2
tomcat - update to 9.0.96-2
tomcat-help - update to 9.0.96-2
tomcat - addressed in versions 9.0.97-1.fc40, 9.0.97-1.fc41, 9.0.97-1.fc42, 9.0.98-1.fc40, 9.0.98-1.fc41
IBM Security SOAR - update to 51.0.4.1
External References
Related Security Bulletins
- Cross-site scripting in Apache Tomcat
- openEuler 22.03 LTS SP1 update for tomcat
- openEuler 20.03 LTS SP4 update for tomcat
- openEuler 22.03 LTS SP3 update for tomcat
- openEuler 22.03 LTS SP4 update for tomcat
- openEuler 24.03 LTS update for tomcat
- Multiple vulnerabilities in cPanel EasyApache
- Fedora 42 update for tomcat
- Fedora 41 update for tomcat
- Fedora 40 update for tomcat
- Fedora 41 update for tomcat
- Fedora 40 update for tomcat
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Security SOAR
- IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) update for Apache Tomcat
- IBM Power Hardware Management Console (HMC) update for Apache Tomcat
- XSS in Traffix SDC Apache Tomcat component
- Multiple vulnerabilities in IBM DevOps Release
- Multiple vulnerabilities in IBM Rational Build Forge
- Dell NetWorker update for Apache Tomcat