CVE-2018-1304

MEDIUM LAB

Apache Tomcat <9.0.5-7.0.85 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2018-1304. PoCs published by knqyf263, thariyarox.

AI-analyzed exploit summary This is a minimal Java servlet example demonstrating a vulnerable endpoint, but it lacks exploit logic or payload delivery. It only serves a static HTML page and does not exploit CVE-2018-1304.

Description

The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.

Exploits (2)

nomisec STUB 3 stars
by knqyf263 · poc
https://github.com/knqyf263/CVE-2018-1304

This is a minimal Java servlet example demonstrating a vulnerable endpoint, but it lacks exploit logic or payload delivery. It only serves a static HTML page and does not exploit CVE-2018-1304.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Apache Tomcat (version not specified)
Auth required
Prerequisites: Admin role access
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec STUB
by thariyarox · poc
https://github.com/thariyarox/tomcat_CVE-2018-1304_testing

This is a simple Java servlet example demonstrating a restricted page, but it does not contain any exploit code or vulnerability demonstration for CVE-2018-1304. It lacks offensive techniques or PoC logic.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Apache Tomcat (version not specified)
Auth required
Prerequisites: Access to a Tomcat server with admin role
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (40)

Core 40
Core References
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:1448
Patch, Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20180706-0001/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/103170
Patch, Third Party Advisory x_refsource_confirm
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:1449
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:1450
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2018/dsa-4281
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2939
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:0465
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3665-1/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1040427
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:1320
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:1451
Issue Tracking, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2018/03/msg00004.html
Patch, Third Party Advisory x_refsource_confirm
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2018/07/msg00044.html
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:0466
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:1447
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2018/06/msg00008.html
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:2205

Scores

CVSS v3 5.9
EPSS 0.0304
EPSS Percentile 87.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (21)
apache/tomcat 8.0.0 rc1
apache/tomcat 9.0.0 milestone1 (27 CPE variants)
apache/tomcat 7.0.0 - 7.0.84
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 17.10
canonical/ubuntu_linux 18.04
debian/debian_linux 7.0
debian/debian_linux 8.0
debian/debian_linux 9.0
... and 11 more
Published Feb 28, 2018
Tracked Since Feb 18, 2026