Moderate severityNVD Advisory· Published Nov 26, 2010· Updated Jun 16, 2026
CVE-2010-4172
CVE-2010-4172
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tomcat:tomcatMaven | >= 7.0.0, < 7.0.5 | 7.0.5 |
org.apache.tomcat:tomcatMaven | >= 6.0.12, <= 6.0.29 | — |
Affected products
21cpe:2.3:a:apache:tomcat:6.0.12:*:*:*:*:*:*:*+ 19 more
- cpe:2.3:a:apache:tomcat:6.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.15:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.16:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.17:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.18:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.19:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.20:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.24:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.26:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.27:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.28:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.29:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.4:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
36- tomcat.apache.org/security-7.htmlnvdPatchVendor Advisory
- www.securityfocus.com/bid/45015nvdExploit
- secunia.com/advisories/42337nvdVendor Advisory
- www.vupen.com/english/advisories/2010/3047nvdVendor Advisory
- github.com/advisories/GHSA-c78g-qwpw-2jgvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2010-4172ghsaADVISORY
- bugzilla.redhat.com/show_bug.cginvdWEB
- github.com/apache/tomcat/commit/5971f9392edc6d70808b2599b062b050fcd11d23ghsaWEB
- lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlghsaWEB
- marc.infoghsaWEB
- tomcat.apache.org/security-7.htmlghsaWEB
- www.redhat.com/support/errata/RHSA-2011-0896.htmlghsaWEB
- www.redhat.com/support/errata/RHSA-2011-0897.htmlghsaWEB
- www.securityfocus.com/archive/1/514866/100/0/threadedghsaWEB
- www.ubuntu.com/usn/USN-1048-1ghsaWEB
- www.vupen.com/english/advisories/2010/3047ghsaWEB
- www.vupen.com/english/advisories/2011/0203ghsaWEB
- archives.neohapsis.com/archives/fulldisclosure/2010-11/0285.htmlnvd
- lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlnvd
- marc.infonvd
- secunia.com/advisories/43019nvd
- secunia.com/advisories/45022nvd
- secunia.com/advisories/57126nvd
- securitytracker.com/idnvd
- support.apple.com/kb/HT5002nvd
- support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5098550.htmlnvd
- svn.apache.org/viewvcnvd
- svn.apache.org/viewvcnvd
- tomcat.apache.org/security-6.htmlnvd
- www.redhat.com/support/errata/RHSA-2011-0791.htmlnvd
- www.redhat.com/support/errata/RHSA-2011-0896.htmlnvd
- www.redhat.com/support/errata/RHSA-2011-0897.htmlnvd
- www.securityfocus.com/archive/1/514866/100/0/threadednvd
- www.ubuntu.com/usn/USN-1048-1nvd
- www.vupen.com/english/advisories/2011/0203nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/63422nvd
News mentions
0No linked articles in our index yet.