Impact
This vulnerability is an improper neutralization of script‑related HTML tags that allows a basic client‑side XSS flaw (CWE‑79, CWE‑80) in the number‑guess example page. An runs in the victim’s browser, potentially exposing sensitive data or executing unintended actions if the user interacts with the page.
Affected Systems
Apache Tomcat releases 7.0.0 through 7.0.109, 8.5.0 through 8.5.100, 9.0.0.M1 through 9.0.118, 10.1.0-M1 through 10.1.55, and 11.0.0-M1 through 11.0.22, including other end‑of‑support versions.
Risk and Exploitability
The flaw can be triggered by accessing the number‑guess example page and requires only a victim to visit the vulnerable URL. The CVSS score of 6.1 indicates a medium severity. The EPSS score of 3% reflects a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Because the attack vector is client‑side, exploitation is limited to users who access the example page; no elevated privileges or attacker‑controlled server side code are required.
OpenCVE Enrichment
Ubuntu USN