Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

9.010.010.111.0201720182019202020212022202320242025202620272028

Недавние уязвимости Tomcat

Количество 1 466

github логотип

GHSA-rh8q-vjgf-gf74

около 4 лет назад

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-w3j5-q8f2-3cqq

около 4 лет назад

Concurrent Execution using Shared Resource with Improper Synchronization in Apache Tomcat

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-372q-33vh-8mpc

около 4 лет назад

Inconsistent documentation in Apache Tomcat

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-fjwp-r6fm-q6qw

около 4 лет назад

Apache Tomcat allows remote attackers to read data that was intended to be associated with a different request

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-73rx-3f9r-x949

около 4 лет назад

Insufficient Verification of Data Authenticity in Apache Tomcat

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xjgh-84hx-56c5

около 4 лет назад

Unrestricted Upload of File with Dangerous Type Apache Tomcat

CVSS3: 8.1
EPSS: Критический
github логотип

GHSA-68g5-8q7f-m384

около 4 лет назад

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-h3ch-5pp2-vh6w

около 4 лет назад

Improper socket reuse in Apache Tomcat

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2022-25762

около 4 лет назад

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2022-25762

около 4 лет назад

If a web application sends a WebSocket message concurrently with the W ...

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-rh8q-vjgf-gf74

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

CVSS3: 5.3
18%
Средний
около 4 лет назад
github логотип
GHSA-w3j5-q8f2-3cqq

Concurrent Execution using Shared Resource with Improper Synchronization in Apache Tomcat

CVSS3: 7.5
16%
Средний
около 4 лет назад
github логотип
GHSA-372q-33vh-8mpc

Inconsistent documentation in Apache Tomcat

CVSS3: 5.3
6%
Низкий
около 4 лет назад
github логотип
GHSA-fjwp-r6fm-q6qw

Apache Tomcat allows remote attackers to read data that was intended to be associated with a different request

CVSS3: 7.5
7%
Низкий
около 4 лет назад
github логотип
GHSA-73rx-3f9r-x949

Insufficient Verification of Data Authenticity in Apache Tomcat

CVSS3: 4.3
8%
Низкий
около 4 лет назад
github логотип
GHSA-xjgh-84hx-56c5

Unrestricted Upload of File with Dangerous Type Apache Tomcat

CVSS3: 8.1
100%
Критический
около 4 лет назад
github логотип
GHSA-68g5-8q7f-m384

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

CVSS3: 7.5
10%
Средний
около 4 лет назад
github логотип
GHSA-h3ch-5pp2-vh6w

Improper socket reuse in Apache Tomcat

CVSS3: 8.6
8%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-25762

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

CVSS3: 8.6
8%
Низкий
около 4 лет назад
debian логотип
CVE-2022-25762

If a web application sends a WebSocket message concurrently with the W ...

CVSS3: 8.6
8%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться