S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-37573 Scanner

CVE-2021-37573 scanner - Cross-Site Scripting (XSS) vulnerability in TTiny Java Web Server and Servlet Container (TJWS)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
5.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-37573
6.1
CVSS

A reflected cross-site scripting (XSS) vulnerability in the web server TTiny Java Web Server and Servlet Container (TJWS) <=1.115 allows an adversary to inject malicious code on the server's "404 Page not Found" error page

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

TTiny Java Web Server and Servlet Container (TJWS) is an open-source web server and servlet container that is designed to be lightweight and fast. TJWS is widely used by developers who are looking to build fast and efficient web applications, particularly as it offers support for Java Servlet API.

Recently, a severe vulnerability was detected within TJWS, affecting TJWS versions up to 1.115. This vulnerability, identified as CVE-2021-37573, allowed attackers to inject malicious code within the server's "404 Page not Found" error page. Attackers could exploit this vulnerability to inject malicious scripts or HTML code, which could lead to various attacks like cross-site scripting (XSS) and session hijacking.

If exploited, this vulnerability can have serious consequences. Attackers can gain access to user data and sensitive information, which can then be used for various nefarious activities, including identity theft, financial fraud, and espionage. Additionally, the vulnerability allows for the exploitation of user sessions, giving the attacker unauthorized access to the user's account.

At s4e.io, we offer a wide range of tools and services to help ensure that your digital assets are secure and protected. Our platform offers detailed vulnerability reports, as well as real-time alerts and notifications, which can help you stay ahead of potential threats. With our pro features, you can easily and quickly learn about vulnerabilities in your digital assets, and take appropriate action to mitigate any risks. Try our platform today and stay secure!

 

REFERENCES

Solution Advice

Fortunately, there are a few precautions that can be taken to protect against this vulnerability:

  • Install the latest security updates for TJWS
  • Use a web application firewall (WAF) or intrusion detection system (IDS) to monitor web traffic and block malicious traffic
  • Regularly scan your web application with vulnerability scanners to detect any potential vulnerabilities

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-37573 scanner - Cross-Site Scripting (XSS) vulnerability in TTiny Java Web Server and Servlet Container (TJWS) | S4E