Apache Tomcat 11.0.0.M1 < 11.0.0.M3 multiple vulnerabilities

medium Nessus Plugin ID 171714

Version 1.9

May 25, 2023, 5:09 PM

  • IAVM reference

Plugin Feed: 202305251709

Version 1.8

Apr 11, 2023, 2:08 PM

  • Plugin metadata

Plugin Feed: 202304111408

Version 1.7

Apr 4, 2023, 12:12 PM

  • Plugin metadata

Plugin Feed: 202304041212

Version 1.6

Mar 28, 2023, 2:03 PM

  • CVSSv2 severity (based on CVE-2023-28708, severity decreased from "High" to "Medium")
  • CVSSv3 severity (based on CVE-2023-28708, severity decreased from "High" to "Medium")
  • CVSS metrics ("CVSSv2 score" changed from 7.8 to 5.0. "CVSSv2 score" changed from 7.8 to 5.0. "CVSSv2 score" changed from 7.8 to 5.0. "CVSSv2 vector" changed from "CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C" to "CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N". "CVSSv3 vector" changed from "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" to "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N". "CVSSv3 score" changed from 7.5 to 4.3. "CVSSv2 vector" changed from "CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C" to "CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N". "CVSSv3 vector" changed from "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" to "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N". "CVSSv3 score" changed from 7.5 to 4.3. "CVSSv2 vector" changed from "CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C" to "CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N". "CVSSv3 vector" changed from "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" to "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N". "CVSSv3 score" changed from 7.5 to 4.3. "CVSSv2 vector" changed from "CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C" to "CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N")
  • CVSSv2 score source (changed from "CVE-2023-24998" to "CVE-2023-28708")
  • CVSSv3 score source (set to "CVE-2023-28708")

Plugin Feed: 202303281403

Version 1.5

Mar 27, 2023, 6:02 PM

  • IAVM reference

Plugin Feed: 202303271802

Version 1.4

Mar 24, 2023, 10:05 AM

  • IAVM reference

Plugin Feed: 202303241005

Version 1.3

Mar 22, 2023, 8:06 PM

  • Regenerated based on advisory update

Plugin Feed: 202303222006

Version 1.2

Mar 2, 2023, 2:01 PM

  • CVSS metrics ("CVSSv2 score" changed from "7.5" to "7.8". "CVSSv2 score" changed from "7.5" to "7.8". "CVSSv2 score" changed from "7.5" to "7.8". "CVSSv3 score" changed from "9.8" to "7.5". "CVSSv3 vector" changed from "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" to "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H". "CVSSv2 vector" changed from "CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P" to "CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C". "CVSSv3 vector" changed from "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" to "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H". "CVSSv3 score" changed from "9.8" to "7.5". "CVSSv2 vector" changed from "CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P" to "CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C". "CVSSv3 vector" changed from "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" to "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H". "CVSSv3 score" changed from "9.8" to "7.5". "CVSSv2 vector" changed from "CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P" to "CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C". "CVSSv3 vector" changed from "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" to "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H")
  • CVSSv3 score source (set to "CVE-2023-24998")

Plugin Feed: 202303021401

Version 1.1

Feb 23, 2023, 8:04 PM

  • IAVM reference
  • STIG Severity (set to "I")

Plugin Feed: 202302232004

Version 1.0

Feb 21, 2023, 8:11 PM

  • New

Plugin Feed: 202302212011

* Changelogs are generally available for changes made after Nov 1, 2022