Security restrictions bypass in Apache Tomcat - CVE-2018-8034
Published: June 25, 2018 / Updated: July 24, 2018
Vulnerability identifier: #VU13992
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8034
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists due to host name verification when using TLS with the WebSocket client was missing. A remote unauthenticated attacker can bypass security restrictions when using TLS.
Affected software
Apache Tomcat
JBoss Enterprise Web Server
Amazon Linux AMI
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
Dell Support Assist Enterprise
Storage Defender Copy Data Management
EMC Cloud Tiering Appliance
Fuse
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
tomcat
JBoss Enterprise Web Server
Amazon Linux AMI
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
Dell Support Assist Enterprise
Storage Defender Copy Data Management
EMC Cloud Tiering Appliance
Fuse
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
tomcat
How to mitigate CVE-2018-8034
The vulnerability is addressed in the versions 7.0.90, 9.0.10.
Apache Tomcat - addressed in versions 7.0.90, 9.0.10
Dell Support Assist Enterprise - update to 4.00.06.00
Fuse - update to 7.5.0
Storage Defender Copy Data Management - update to 2.2.28.0
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
tomcat - addressed in versions 8.0.53-1.fc27, 8.5.32-1.fc28
EMC Cloud Tiering Appliance - addressed in versions 13.0.0.2.29, 13.1.0.2.20
Dell Support Assist Enterprise - update to 4.00.06.00
Fuse - update to 7.5.0
Storage Defender Copy Data Management - update to 2.2.28.0
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
tomcat - addressed in versions 8.0.53-1.fc27, 8.5.32-1.fc28
EMC Cloud Tiering Appliance - addressed in versions 13.0.0.2.29, 13.1.0.2.20
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache Tomcat
- Amazon Linux AMI update for tomcat8
- Amazon Linux AMI update for tomcat7, tomcat80
- Debian update for tomcat8
- OpenSUSE Linux update for tomcat
- OpenSUSE Linux update for tomcat
- Red Hat update for tomcat
- Red Hat update for Red Hat JBoss Web Server 5.0 Service Pack 2
- Red Hat update for pki-deps:10.6
- Multiple vulnerabilities in Red Hat Fuse
- Multiple vulnerabilities in Dell EMC Cloud Tiering Appliance
- Multiple vulnerabilities in Dell EMC Unity Family
- Multiple vulnerabilities in Dell Support Assist Enterprise
- Fedora 28 update for tomcat
- Fedora 27 update for tomcat
- Multiple vulnerabilities in IBM Storage Defender Copy Data Management