Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

9.010.010.111.0201720182019202020212022202320242025202620272028

Недавние уязвимости Tomcat

Количество 1 533

fstec логотип

BDU:2022-04494

больше 10 лет назад

Уязвимость реализации Realm сервера приложений Apache Tomcat, связанная с раскрытием информации через несоответствие, позволяющая нарушителю определить все существующие имена пользователей

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:1281-1

около 11 лет назад

Security update for tomcat

EPSS: Средний
debian логотип

CVE-2014-7810

больше 11 лет назад

The Expression Language (EL) implementation in Apache Tomcat 6.x befor ...

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2014-7810

больше 11 лет назад

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2014-0230

больше 11 лет назад

Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0 ...

CVSS2: 7.8
EPSS: Средний
nvd логотип

CVE-2014-0230

больше 11 лет назад

Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.

CVSS2: 7.8
EPSS: Средний
ubuntu логотип

CVE-2014-7810

больше 11 лет назад

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2014-0230

больше 11 лет назад

Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.

CVSS2: 7.8
EPSS: Средний
redhat логотип

CVE-2014-7810

больше 11 лет назад

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.

CVSS2: 5.8
EPSS: Средний
oracle-oval логотип

ELSA-2015-0991

больше 11 лет назад

ELSA-2015-0991: tomcat6 security and bug fix update (MODERATE)

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
fstec логотип
BDU:2022-04494

Уязвимость реализации Realm сервера приложений Apache Tomcat, связанная с раскрытием информации через несоответствие, позволяющая нарушителю определить все существующие имена пользователей

CVSS3: 5.9
8%
Низкий
больше 10 лет назад
suse-cvrf логотип
SUSE-SU-2015:1281-1

Security update for tomcat

14%
Средний
около 11 лет назад
debian логотип
CVE-2014-7810

The Expression Language (EL) implementation in Apache Tomcat 6.x befor ...

CVSS2: 5
14%
Средний
больше 11 лет назад
nvd логотип
CVE-2014-7810

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.

CVSS2: 5
14%
Средний
больше 11 лет назад
debian логотип
CVE-2014-0230

Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0 ...

CVSS2: 7.8
20%
Средний
больше 11 лет назад
nvd логотип
CVE-2014-0230

Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.

CVSS2: 7.8
20%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2014-7810

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.

CVSS2: 5
14%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2014-0230

Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.

CVSS2: 7.8
20%
Средний
больше 11 лет назад
redhat логотип
CVE-2014-7810

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.

CVSS2: 5.8
14%
Средний
больше 11 лет назад
oracle-oval логотип
ELSA-2015-0991

ELSA-2015-0991: tomcat6 security and bug fix update (MODERATE)

21%
Средний
больше 11 лет назад

Уязвимостей на страницу


Поделиться