Tomcat host manager xss - name field
Published Jun 4, 2008
5.3
MEDIUMCVSS 4.0
EPSS 9.78%
Description
Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.
Affected products
No data.
- 5.5.9
- 5.5.10
- 5.5.11
- 5.5.12
- 5.5.13
- 5.5.14
- 5.5.15
- 5.5.16
- 5.5.17
- 5.5.18
- 5.5.19
- 5.5.20
- 5.5.21
- 5.5.22
- 5.5.23
- 5.5.24
- 5.5.25
- 5.5.26
- 6.0.0
- 6.0.1
- 6.0.2
- 6.0.3
- 6.0.4
- 6.0.5
- 6.0.6
- 6.0.7
- 6.0.8
- 6.0.9
- 6.0.10
- 6.0.11
- 6.0.12
- 6.0.13
- 6.0.14
- 6.0.15
- 6.0.16
No data.
RHAPS Version 2 for RHEL 4
tomcat5-0:5.5.23-0jpp_4rh.9
Fixed · RHSA-2008:0862
Red Hat Developer Suite V.3
tomcat5-0:5.5.23-0jpp_12rh
Fixed · RHSA-2008:0864
Red Hat Enterprise Linux 5
tomcat5-0:5.5.23-0jpp.7.el5_2.1
Fixed · RHSA-2008:0648
Red Hat Network Satellite Server v 5.0
tomcat5-0:5.0.30-0jpp_12rh
Fixed · RHSA-2008:1007
Red Hat Network Satellite Server v 5.1
tomcat5-0:5.0.30-0jpp_12rh
Fixed · RHSA-2008:1007
| Product | Package | State | Advisory |
|---|---|---|---|
| RHAPS Version 2 for RHEL 4 | tomcat5-0:5.5.23-0jpp_4rh.9 | Fixed | RHSA-2008:0862 |
| Red Hat Developer Suite V.3 | tomcat5-0:5.5.23-0jpp_12rh | Fixed | RHSA-2008:0864 |
| Red Hat Enterprise Linux 5 | tomcat5-0:5.5.23-0jpp.7.el5_2.1 | Fixed | RHSA-2008:0648 |
| Red Hat Network Satellite Server v 5.0 | tomcat5-0:5.0.30-0jpp_12rh | Fixed | RHSA-2008:1007 |
| Red Hat Network Satellite Server v 5.1 | tomcat5-0:5.0.30-0jpp_12rh | Fixed | RHSA-2008:1007 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (26 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 9.78% (0.09776) | 95.40th | v5 (v2026.06.15) |
| Jun 15, 2026 | 9.78% (0.09776) | 94.91th | v5 (v2026.06.15) |
| Nov 17, 2025 | 59.30% (0.59297) | 98.14th | v4 (v2025.03.14) |
| Mar 30, 2025 | 49.11% (0.49114) | 97.54th | v4 (v2025.03.14) |
| Mar 29, 2025 | 53.69% (0.53694) | 97.08th | v4 (v2025.03.14) |
| Mar 17, 2025 | 49.11% (0.49114) | 97.50th | v4 (v2025.03.14) |
| Mar 1, 2025 | 6.84% (0.06836) | 93.96th | v3 (v2023.03.01) |
| Jan 22, 2025 | 4.61% (0.04613) | 92.52th | v3 (v2023.03.01) |
| Nov 6, 2024 | 6.34% (0.06343) | 93.84th | v3 (v2023.03.01) |
| Jun 10, 2024 | 10.00% (0.09996) | 94.89th | v3 (v2023.03.01) |
| May 5, 2024 | 10.91% (0.10906) | 95.07th | v3 (v2023.03.01) |
| Feb 24, 2024 | 11.78% (0.11783) | 95.13th | v3 (v2023.03.01) |
| Dec 14, 2023 | 12.86% (0.12863) | 94.95th | v3 (v2023.03.01) |
| Nov 8, 2023 | 21.62% (0.21617) | 95.94th | v3 (v2023.03.01) |
| Oct 2, 2023 | 14.47% (0.14468) | 95.07th | v3 (v2023.03.01) |
| Aug 29, 2023 | 15.26% (0.15259) | 95.15th | v3 (v2023.03.01) |
| Jul 25, 2023 | 17.94% (0.17942) | 95.47th | v3 (v2023.03.01) |
| Jun 18, 2023 | 26.27% (0.26266) | 96.08th | v3 (v2023.03.01) |
| May 12, 2023 | 27.44% (0.27444) | 96.10th | v3 (v2023.03.01) |
| Apr 4, 2023 | 27.10% (0.27098) | 96.05th | v3 (v2023.03.01) |
| Mar 7, 2023 | 18.16% (0.18165) | 95.31th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.34% (0.07344) | 92.59th | v2 (v2022.01.01) |
| Feb 13, 2023 | 7.34% (0.07344) | 92.29th | v2 (v2022.01.01) |
| Feb 3, 2023 | 5.24% (0.05242) | 89.44th | v2 (v2022.01.01) |
| Apr 1, 2022 | 7.34% (0.07344) | 91.87th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.34% (0.07344) | 80.64th | v2 (v2022.01.01) |
References (72)
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=123376588623823&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=139344343412337&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=tomcat-user&m=121244319501278&w=2 mailing-listx_refsource_MLIST
- http://secunia.com/advisories/30500 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/30592 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/30967 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31639 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31865 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31891 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/32120 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/32222 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/32266 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/33797 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/33999 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34013 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/37460 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/57126 third-party-advisoryx_refsource_SECUNIA
- http://support.apple.com/kb/HT3216 x_refsource_CONFIRM
- http://support.avaya.com/elmodocs2/security/ASA-2008-401.htm x_refsource_CONFIRM
- http://tomcat.apache.org/security-5.html x_refsource_CONFIRM
- http://tomcat.apache.org/security-6.html x_refsource_CONFIRM
- http://www.debian.org/security/2008/dsa-1593 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:188 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/support/errata/RHSA-2008-0648.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0862.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0864.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/492958/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/507985/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/29502 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/31681 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1020624 vdb-entryx_refsource_SECTRACK
- http://www.vmware.com/security/advisories/VMSA-2009-0002.html x_refsource_CONFIRM
- http://www.vmware.com/security/advisories/VMSA-2009-0016.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2008/1725 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/2780 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/2823 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/0320 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/0503 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/3316 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/errata/RHSA-2008:0648
- https://access.redhat.com/errata/RHSA-2008:0862
- https://access.redhat.com/errata/RHSA-2008:0864
- https://access.redhat.com/errata/RHSA-2008:1007
- https://access.redhat.com/security/cve/CVE-2008-1947 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=446393 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42816 vdb-entryx_refsource_XF
- https://github.com/advisories/GHSA-f98p-9pp6-7q6c Advisory
- https://github.com/apache/tomcat/commit/49c71fc59c1b8f8da77aea9eb53e61db168aebab
- https://github.com/apache/tomcat/commit/5f00d434c8dc11bd49ce0b4b56fe889839056030
- https://github.com/apache/tomcat/commit/78ad0fcbe29c824f1f2e45a4e2716247b033250a
- https://github.com/apache/tomcat/commit/ab6a6c41ac972c845717c9d639f0335865afab4d
- https://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5@%3Cdev.tomcat.apache.org%3E
- https://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
- https://nvd.nist.gov/vuln/detail/CVE-2008-1947
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11534 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6009 vdb-entrysignaturex_refsource_OVAL
- https://web.archive.org/web/20200514224656/http://www.securityfocus.com/archive/1/507985/100/0/threaded
- https://web.archive.org/web/20201208011750/http://www.securityfocus.com/archive/1/492958/100/0/threaded
- https://www.cve.org/CVERecord?id=CVE-2008-1947
- https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00712.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00859.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00889.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.