Количество 18
Количество 18
BDU:2026-06931
Уязвимость сервера приложений Apache Tomcat, связанная с недостатками процедуры аутентификации, позволяющая нарушителю повысить свои привилегии
ROS-20260506-73-0030
Уязвимость tomcat-native
ROS-20260506-73-0029
Уязвимость tomcat11
ROS-20260506-73-0028
Уязвимость tomcat10
ROS-20260506-73-0027
Уязвимость tomcat
CVE-2026-29145
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.
CVE-2026-29145
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.
CVE-2026-29145
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.
CVE-2026-29145
CLIENT_CERT authentication does not fail as expected for some scenario ...
GHSA-95jq-rwvf-vjx4
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
openSUSE-SU-2026:20612-1
Security update for tomcat10
openSUSE-SU-2026:20611-1
Security update for tomcat
openSUSE-SU-2026:20595-1
Security update for tomcat11
SUSE-SU-2026:1604-1
Security update for tomcat
SUSE-SU-2026:1603-1
Security update for tomcat10
SUSE-SU-2026:1572-1
Security update for tomcat
SUSE-SU-2026:1558-1
Security update for tomcat11
RLSA-2026:36790
Important: tomcat9 security, bug fix, and enhancement update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-06931 Уязвимость сервера приложений Apache Tomcat, связанная с недостатками процедуры аутентификации, позволяющая нарушителю повысить свои привилегии | CVSS3: 9.1 | 1% Низкий | 4 месяца назад | |
ROS-20260506-73-0030 Уязвимость tomcat-native | CVSS3: 9.1 | 1% Низкий | 3 месяца назад | |
ROS-20260506-73-0029 Уязвимость tomcat11 | CVSS3: 9.1 | 1% Низкий | 3 месяца назад | |
ROS-20260506-73-0028 Уязвимость tomcat10 | CVSS3: 9.1 | 1% Низкий | 3 месяца назад | |
ROS-20260506-73-0027 Уязвимость tomcat | CVSS3: 9.1 | 1% Низкий | 3 месяца назад | |
CVE-2026-29145 CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue. | CVSS3: 9.1 | 1% Низкий | 4 месяца назад | |
CVE-2026-29145 CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue. | CVSS3: 5.9 | 1% Низкий | 4 месяца назад | |
CVE-2026-29145 CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue. | CVSS3: 9.1 | 1% Низкий | 4 месяца назад | |
CVE-2026-29145 CLIENT_CERT authentication does not fail as expected for some scenario ... | CVSS3: 9.1 | 1% Низкий | 4 месяца назад | |
GHSA-95jq-rwvf-vjx4 Apache Tomcat: CLIENT_CERT authentication does not fail as expected | CVSS3: 9.1 | 1% Низкий | 4 месяца назад | |
openSUSE-SU-2026:20612-1 Security update for tomcat10 | 3 месяца назад | |||
openSUSE-SU-2026:20611-1 Security update for tomcat | 3 месяца назад | |||
openSUSE-SU-2026:20595-1 Security update for tomcat11 | 3 месяца назад | |||
SUSE-SU-2026:1604-1 Security update for tomcat | 3 месяца назад | |||
SUSE-SU-2026:1603-1 Security update for tomcat10 | 3 месяца назад | |||
SUSE-SU-2026:1572-1 Security update for tomcat | 3 месяца назад | |||
SUSE-SU-2026:1558-1 Security update for tomcat11 | 3 месяца назад | |||
RLSA-2026:36790 Important: tomcat9 security, bug fix, and enhancement update | 21 день назад |
Уязвимостей на страницу