When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.
CVE-2018-11784
Score elevated to 9.0 because EPSS predicts 94% probability of exploitation within the next 30 days (top 0.2% of all CVEs). NVD baseline CVSS 4.3 retained for reference. Confidence: see factors.
- 84 internet-exposed hosts are running an affected version right now
- High exploitation likelihood — EPSS 94%
A fix is available — apply it.
84 internet-exposed hosts are running an affected version of CVE-2018-11784 right now.
EchelonGraph is the only CVE feed that fuses live vulnerability intelligence with its own live internet-exposure radar — so you see not just that a CVE is exploited, but how much of the internet is exposed to it right now.
- CVSS v3
- 4.3
- EG Score
- 9.0(high)
- EPSS
- 99.8%
- KEV
- Not listed
Published
October 4, 2018
Last Modified
November 21, 2024
References (78)
- security@apachehttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00030.html
- security@apachehttp://lists.opensuse.org/opensuse-security-announce/2019-07/msg00056.html
- security@apachehttp://packetstormsecurity.com/files/163456/Apache-Tomcat-9.0.0M1-Open-Redirect.html
- security@apachehttp://www.securityfocus.com/bid/105524
- security@apachehttps://access.redhat.com/errata/RHSA-2019:0130
- security@apachehttps://access.redhat.com/errata/RHSA-2019:0131
- security@apachehttps://access.redhat.com/errata/RHSA-2019:0485
- security@apachehttps://access.redhat.com/errata/RHSA-2019:1529
- security@apachehttps://kc.mcafee.com/corporate/index?page=content&id=SB10284
- security@apachehttps://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba%40%3Cdev.tomcat.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/23134c9b5a23892a205dc140cdd8c9c0add233600f76b313dda6bd75%40%3Cannounce.tomcat.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/5c0e00fd31efc11e147bf99d0f03c00a734447d3b131ab0818644cdb%40%3Cdev.tomcat.apache.org%3E
Patch Availability(7)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | tomcat8-user (8.0.32-1ubuntu1.8) @ xenial | 2026-05-28 | ubuntu |
| redhat | pki-deps:10.6-8000020190524054914.55190bc5 | 2019-06-18 | redhat |
| redhat | tomcat-0:7.0.76-9.el7_6 | 2019-03-13 | redhat |
| redhat | tomcat | 2019-01-22 | redhat |
| redhat | tomcat-native-0:1.2.17-18.redhat_18.ep7.el7 | 2019-01-22 | redhat |
| redhat | jws5-tomcat-0:9.0.7-12.redhat_12.1.el7jws | 2018-10-03 | redhat |
| redhat | patch | 2018-10-03 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(1 across 1 ecosystem)
Maven(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.apache.tomcat.embed:tomcat-embed-core | 9.0.1 ... 9.0.8 (9 versions) | 9.0.12 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
All Vendor Advisories
(7)
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
- Red HatRHSA-2018:2867MODERATE2018-10-03
RHSA-2018:2867 — Moderate
- Red HatRHSA-2018:2868MODERATE2018-10-03
RHSA-2018:2868 — Moderate
- Red HatRHSA-2019:0130MODERATE2018-10-03
RHSA-2019:0130 — Moderate
- Red HatRHSA-2019:0131MODERATE2018-10-03
RHSA-2019:0131 — Moderate
- Red HatRHSA-2019:0485MODERATE2018-10-03
RHSA-2019:0485 — Moderate
- Red HatRHSA-2019:1529MODERATE2018-10-03
RHSA-2019:1529 — Moderate
- UbuntuUSN-3787-1MEDIUM
Tomcat vulnerability
Data Freshness Timeline
(refreshed 5× in last 7d / 14× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-22 21:29 UTCEG score recompute▲ 4.70
- 2026-07-22 21:29 UTCVendor advisory
- 2026-07-21 04:47 UTCOSV refresh
- 2026-07-19 02:26 UTCEPSS rescore
- 2026-07-19 02:26 UTCEPSS rescore
- 2026-07-12 05:43 UTCEPSS rescore
- 2026-07-11 08:24 UTCEPSS rescore
- 2026-07-04 00:26 UTCOSV refresh
- 2026-07-01 15:03 UTCEPSS rescore
- 2026-07-01 15:03 UTCEPSS rescore
- 2026-06-29 14:03 UTCEPSS rescore
- 2026-06-25 13:47 UTCEPSS rescore
- 2026-06-25 13:47 UTCEPSS rescore
- 2026-06-23 21:30 UTCEPSS rescore
- 2026-06-22 14:23 UTCEPSS rescore
- 2026-06-21 01:57 UTCEPSS rescore
- 2026-06-21 01:57 UTCEPSS rescore
- 2026-06-15 17:45 UTCEPSS rescore
- 2026-06-15 12:13 UTCOSV refresh
- 2026-06-13 22:58 UTCEPSS rescore
- 2026-06-13 22:58 UTCEPSS rescore
- 2026-06-12 23:09 UTCEPSS rescore
- 2026-06-11 13:57 UTCEPSS rescore
- 2026-06-10 22:16 UTCEPSS rescore
- 2026-06-06 13:45 UTCEPSS rescore
Show 15 moreShow fewer
- 2026-06-06 13:45 UTCEPSS rescore
- 2026-06-05 22:45 UTCEPSS rescore
- 2026-06-05 22:44 UTCEPSS rescore
- 2026-06-05 06:08 UTCEPSS rescore
- 2026-06-05 06:08 UTCEPSS rescore
- 2026-06-01 13:49 UTCEPSS rescore
- 2026-05-31 00:14 UTCEPSS rescore
- 2026-05-31 00:14 UTCEPSS rescore
- 2026-05-28 13:42 UTCEPSS rescore
- 2026-05-28 13:42 UTCEPSS rescore
- 2026-05-28 02:32 UTCEG score recompute
- 2026-05-28 02:32 UTCVendor advisory
- 2026-05-27 13:38 UTCEPSS rescore
- 2026-05-27 13:38 UTCEPSS rescore
- 2026-05-23 09:31 UTCOSV refresh
Publicly available exploits
(2 references)Working exploit code is in the public domain (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- Exploit-DBEDB-50118First seen Jul 13, 2021
Apache Tomcat 9.0.0.M1 - Open Redirect
Open source ↗ - Nucleihttp/cves/2018/CVE-2018-11784.yamlFirst seen Jan 1, 2018
Apache Tomcat - Open Redirect
Open source ↗
Related CVEs(same vendor + same CWE)
Same vendor
10 shownredhat
Frequently asked(5)
What is CVE-2018-11784?
When was CVE-2018-11784 disclosed?
Is CVE-2018-11784 actively exploited?
What is the CVSS score of CVE-2018-11784?
How do I remediate CVE-2018-11784?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2018-11784
Is Your Infrastructure Affected by CVE-2018-11784?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.