Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

ubuntu логотип

CVE-2026-68525

30 дней назад

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2026-68525

30 дней назад

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-68525

30 дней назад

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-68525

30 дней назад

Incorrect Authorization vulnerability in Apache Tomcat's FORM authenti ...

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-h3x4-894j-xpx5

30 дней назад

Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability

CVSS3: 9.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4203-1

8 дней назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4126-1

13 дней назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4119-1

14 дней назад

Security update for tomcat10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4114-1

15 дней назад

Security update for tomcat11

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21823-1

15 дней назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21811-1

16 дней назад

Security update for tomcat11

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21810-1

16 дней назад

Security update for tomcat10

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-68525

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.

CVSS3: 9.1
1%
Низкий
30 дней назад
redhat логотип
CVE-2026-68525

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.

CVSS3: 6.5
1%
Низкий
30 дней назад
nvd логотип
CVE-2026-68525

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.

CVSS3: 9.1
1%
Низкий
30 дней назад
debian логотип
CVE-2026-68525

Incorrect Authorization vulnerability in Apache Tomcat's FORM authenti ...

CVSS3: 9.1
1%
Низкий
30 дней назад
github логотип
GHSA-h3x4-894j-xpx5

Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability

CVSS3: 9.1
1%
Низкий
30 дней назад
suse-cvrf логотип
SUSE-SU-2026:4203-1

Security update for tomcat

8 дней назад
suse-cvrf логотип
SUSE-SU-2026:4126-1

Security update for tomcat

13 дней назад
suse-cvrf логотип
SUSE-SU-2026:4119-1

Security update for tomcat10

14 дней назад
suse-cvrf логотип
SUSE-SU-2026:4114-1

Security update for tomcat11

15 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21823-1

Security update for tomcat

15 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21811-1

Security update for tomcat11

16 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21810-1

Security update for tomcat10

16 дней назад

Уязвимостей на страницу