Tomcat — контейнер сервлетов с открытым исходным кодом
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 533
GHSA-r6cf-cr44-m8rr
Apache Tomcat Leaks Pathname Information via Error Message
GHSA-8g4f-fh7f-4fwh
Apache Tomcat Default Installation Reveals Sensitive Information
GHSA-f436-gr4m-qq5w
The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.
GHSA-rffr-vjp4-vxh3
The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.
GHSA-86fp-jgwm-wgj5
Apache Tomcat XSS Vulnerability
GHSA-8v5p-2cpv-c2x6
Apache Tomcat Source Code Disclosure
GHSA-jxcv-v856-j5vg
Apache Tomcat Source Code Disclosure
GHSA-ppj6-9ppm-3h56
The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).
GHSA-xmf4-j3j7-xj7q
Apache Tomcat DoS Via Requests Including Null Characters
GHSA-jjxj-xvcp-cxv8
Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-r6cf-cr44-m8rr Apache Tomcat Leaks Pathname Information via Error Message | 7% Низкий | больше 4 лет назад | ||
GHSA-8g4f-fh7f-4fwh Apache Tomcat Default Installation Reveals Sensitive Information | 31% Средний | больше 4 лет назад | ||
GHSA-f436-gr4m-qq5w The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages. | 41% Средний | больше 4 лет назад | ||
GHSA-rffr-vjp4-vxh3 The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN. | 4% Низкий | больше 4 лет назад | ||
GHSA-86fp-jgwm-wgj5 Apache Tomcat XSS Vulnerability | 27% Средний | больше 4 лет назад | ||
GHSA-8v5p-2cpv-c2x6 Apache Tomcat Source Code Disclosure | 6% Низкий | больше 4 лет назад | ||
GHSA-jxcv-v856-j5vg Apache Tomcat Source Code Disclosure | 19% Средний | больше 4 лет назад | ||
GHSA-ppj6-9ppm-3h56 The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null). | 27% Средний | больше 4 лет назад | ||
GHSA-xmf4-j3j7-xj7q Apache Tomcat DoS Via Requests Including Null Characters | 8% Низкий | больше 4 лет назад | ||
GHSA-jjxj-xvcp-cxv8 Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet. | 14% Средний | больше 4 лет назад |
Уязвимостей на страницу