GHSA-rh8q-vjgf-gf74 · 嚴重度: medium · 生態: maven — Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a directory via a URL that lacks a trailing / (slash) character.
結論預警: CVE-2015-5345 綜合評估為中等風險(50.1/100):CVSS 技術影響為中級,利用機率偏高(EPSS 18.38%,百分位 97%) 核心證據: EPSS 顯示該漏洞近期被利用的可能性處於高位。 強制指令: 被利用機率偏高—請盤點暴露面並優先安排修補。
風險隨態勢動態變化;本站持續評估並同步更新本頁展示內容。
EPSS 日更估計相對被利用可能性;百分位表示該 CVE 在已評分漏洞中的相對排名(越高表示相對更嚴重)。
| # | 日期 | 舊 EPSS 分數 | 新 EPSS 分數 | 變化(新 − 舊) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 49.88% | 18.38% | -31.50% |
| 2 | 2026-05-13 | 43.33% | 49.88% | +6.55% |
| 3 | 2026-04-28 | — | 43.33% | — |
完整 EPSS 歷史 (共 52 筆)
該 CVE 的 CVSS 指標。
| 底座分 | 版本 | 嚴重度 | 向量 | 可利用性 | 影響 | 分數來源 |
|---|---|---|---|---|---|---|
| 5.3 | 3.0 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
GHSA-rh8q-vjgf-gf74 · 嚴重度: medium · 生態: maven — Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2015-5345 unimportant priority: Debian including 1 source packages (tomcat9), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2015-5345 |
gentoo
|
high | CVE-2015-5345: 1 GLSA(s) (201705-09), 1 atom(s) (www-servers/tomcat); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2015-5345 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2015-5345 |
suse
|
medium | — | https://www.suse.com/security/cve/CVE-2015-5345/ |
ubuntu
|
low | CVE-2015-5345 low priority: Ubuntu including 4 source packages (tomcat6, tomcat7, tomcat8, tomcat9), 36 status rows across 9 suites (artful, bionic, precise, trusty, upstream, wily, xenial, yakkety, zesty): DNE 13, not-affected 10, released 10, ignored 3. | https://ubuntu.com/security/CVE-2015-5345 |
| 廠商 | 產品 | 版本 | 原始 CPE |
|---|---|---|---|
| debian | debian_linux | 7.0 | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* |
| debian | debian_linux | 8.0 | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.0 | cpe:2.3:a:apache:tomcat:6.0.0:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.0 | cpe:2.3:a:apache:tomcat:6.0.0:alpha:*:*:*:*:*:* |
| apache | tomcat | 6.0.1 | cpe:2.3:a:apache:tomcat:6.0.1:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.1 | cpe:2.3:a:apache:tomcat:6.0.1:alpha:*:*:*:*:*:* |
| apache | tomcat | 6.0.2 | cpe:2.3:a:apache:tomcat:6.0.2:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.2 | cpe:2.3:a:apache:tomcat:6.0.2:alpha:*:*:*:*:*:* |
| apache | tomcat | 6.0.2 | cpe:2.3:a:apache:tomcat:6.0.2:beta:*:*:*:*:*:* |
| apache | tomcat | 6.0.4 | cpe:2.3:a:apache:tomcat:6.0.4:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.4 | cpe:2.3:a:apache:tomcat:6.0.4:alpha:*:*:*:*:*:* |
| apache | tomcat | 6.0.10 | cpe:2.3:a:apache:tomcat:6.0.10:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.11 | cpe:2.3:a:apache:tomcat:6.0.11:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.13 | cpe:2.3:a:apache:tomcat:6.0.13:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.14 | cpe:2.3:a:apache:tomcat:6.0.14:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.16 | cpe:2.3:a:apache:tomcat:6.0.16:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.18 | cpe:2.3:a:apache:tomcat:6.0.18:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.20 | cpe:2.3:a:apache:tomcat:6.0.20:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.24 | cpe:2.3:a:apache:tomcat:6.0.24:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.26 | cpe:2.3:a:apache:tomcat:6.0.26:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.28 | cpe:2.3:a:apache:tomcat:6.0.28:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.29 | cpe:2.3:a:apache:tomcat:6.0.29:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.30 | cpe:2.3:a:apache:tomcat:6.0.30:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.32 | cpe:2.3:a:apache:tomcat:6.0.32:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.33 | cpe:2.3:a:apache:tomcat:6.0.33:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.35 | cpe:2.3:a:apache:tomcat:6.0.35:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.36 | cpe:2.3:a:apache:tomcat:6.0.36:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.37 | cpe:2.3:a:apache:tomcat:6.0.37:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.39 | cpe:2.3:a:apache:tomcat:6.0.39:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.41 | cpe:2.3:a:apache:tomcat:6.0.41:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.43 | cpe:2.3:a:apache:tomcat:6.0.43:*:*:*:*:*:*:* |
| apache | tomcat | 6.0.44 | cpe:2.3:a:apache:tomcat:6.0.44:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.0 | cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:* |
| apache | tomcat | 7.0.2 | cpe:2.3:a:apache:tomcat:7.0.2:beta:*:*:*:*:*:* |
| apache | tomcat | 7.0.4 | cpe:2.3:a:apache:tomcat:7.0.4:beta:*:*:*:*:*:* |
| apache | tomcat | 7.0.5 | cpe:2.3:a:apache:tomcat:7.0.5:beta:*:*:*:*:*:* |
| apache | tomcat | 7.0.6 | cpe:2.3:a:apache:tomcat:7.0.6:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.10 | cpe:2.3:a:apache:tomcat:7.0.10:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.11 | cpe:2.3:a:apache:tomcat:7.0.11:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.12 | cpe:2.3:a:apache:tomcat:7.0.12:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.14 | cpe:2.3:a:apache:tomcat:7.0.14:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.16 | cpe:2.3:a:apache:tomcat:7.0.16:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.19 | cpe:2.3:a:apache:tomcat:7.0.19:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.20 | cpe:2.3:a:apache:tomcat:7.0.20:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.21 | cpe:2.3:a:apache:tomcat:7.0.21:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.22 | cpe:2.3:a:apache:tomcat:7.0.22:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.23 | cpe:2.3:a:apache:tomcat:7.0.23:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.25 | cpe:2.3:a:apache:tomcat:7.0.25:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.26 | cpe:2.3:a:apache:tomcat:7.0.26:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.27 | cpe:2.3:a:apache:tomcat:7.0.27:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.28 | cpe:2.3:a:apache:tomcat:7.0.28:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.29 | cpe:2.3:a:apache:tomcat:7.0.29:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.30 | cpe:2.3:a:apache:tomcat:7.0.30:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.32 | cpe:2.3:a:apache:tomcat:7.0.32:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.33 | cpe:2.3:a:apache:tomcat:7.0.33:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.34 | cpe:2.3:a:apache:tomcat:7.0.34:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.35 | cpe:2.3:a:apache:tomcat:7.0.35:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.37 | cpe:2.3:a:apache:tomcat:7.0.37:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.39 | cpe:2.3:a:apache:tomcat:7.0.39:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.40 | cpe:2.3:a:apache:tomcat:7.0.40:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.41 | cpe:2.3:a:apache:tomcat:7.0.41:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.42 | cpe:2.3:a:apache:tomcat:7.0.42:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.47 | cpe:2.3:a:apache:tomcat:7.0.47:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.50 | cpe:2.3:a:apache:tomcat:7.0.50:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.52 | cpe:2.3:a:apache:tomcat:7.0.52:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.53 | cpe:2.3:a:apache:tomcat:7.0.53:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.54 | cpe:2.3:a:apache:tomcat:7.0.54:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.55 | cpe:2.3:a:apache:tomcat:7.0.55:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.56 | cpe:2.3:a:apache:tomcat:7.0.56:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.57 | cpe:2.3:a:apache:tomcat:7.0.57:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.59 | cpe:2.3:a:apache:tomcat:7.0.59:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.61 | cpe:2.3:a:apache:tomcat:7.0.61:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.62 | cpe:2.3:a:apache:tomcat:7.0.62:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.63 | cpe:2.3:a:apache:tomcat:7.0.63:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.64 | cpe:2.3:a:apache:tomcat:7.0.64:*:*:*:*:*:*:* |
| apache | tomcat | 7.0.65 | cpe:2.3:a:apache:tomcat:7.0.65:*:*:*:*:*:*:* |
| apache | tomcat | 8.0.0 | cpe:2.3:a:apache:tomcat:8.0.0:rc1:*:*:*:*:*:* |
| apache | tomcat | 8.0.0 | cpe:2.3:a:apache:tomcat:8.0.0:rc10:*:*:*:*:*:* |
| apache | tomcat | 8.0.0 | cpe:2.3:a:apache:tomcat:8.0.0:rc3:*:*:*:*:*:* |
| apache | tomcat | 8.0.0 | cpe:2.3:a:apache:tomcat:8.0.0:rc5:*:*:*:*:*:* |