Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 43

Количество 43

redos логотип

ROS-20251125-09

8 месяцев назад

Множественные уязвимости tomcat11

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20251125-08

8 месяцев назад

Множественные уязвимости tomcat10

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20251125-07

8 месяцев назад

Множественные уязвимости tomcat

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01882-1

около 1 года назад

Security update for tomcat

EPSS: Низкий
github логотип

GHSA-ff77-26x5-69cr

больше 1 года назад

Apache Tomcat Rewrite rule bypass

EPSS: Низкий
fstec логотип

BDU:2025-05707

больше 1 года назад

Уязвимость сервера приложений Apache Tomcat, связанная с недостатком механизма кодирования или экранирования выходных данных, позволяющая нарушителю оказать влияние на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1537-1

около 1 года назад

Security update for tomcat10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1521-1

около 1 года назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01537-1

около 1 года назад

Security update for tomcat10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01521-1

около 1 года назад

Security update for tomcat

EPSS: Низкий
redos логотип

ROS-20250515-10

около 1 года назад

Множественные уязвимости tomcat

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2025-61795

9 месяцев назад

Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memory usage and application load, it was possible that space for the temporary copies of uploaded parts would be filled faster than GC cleared it, leading to a DoS. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.11, from 10.1.0-M1 through 10.1.46, from 9.0.0.M1 through 9.0.109. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.12 or later, 10.1.47 or later or 9.0.110 or later which fixes the issue.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2025-61795

9 месяцев назад

Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memory usage and application load, it was possible that space for the temporary copies of uploaded parts would be filled faster than GC cleared it, leading to a DoS. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.11, from 10.1.0-M1 through 10.1.46, from 9.0.0.M1 through 9.0.109. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.12 or later, 10.1.47 or later or 9.0.110 or later which fixes the issue.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-61795

9 месяцев назад

Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memory usage and application load, it was possible that space for the temporary copies of uploaded parts would be filled faster than GC cleared it, leading to a DoS. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.11, from 10.1.0-M1 through 10.1.46, from 9.0.0.M1 through 9.0.109. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.12 or later, 10.1.47 or later or 9.0.110 or later which fixes the issue.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-61795

9 месяцев назад

Improper Resource Shutdown or Release vulnerability in Apache Tomcat. ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2025-55752

9 месяцев назад

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Users are re...

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2025-55752

9 месяцев назад

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Users...

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2025-55752

9 месяцев назад

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Use

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2025-55752

9 месяцев назад

Relative Path Traversal vulnerability in Apache Tomcat. The fix for b ...

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-hgrr-935x-pq79

9 месяцев назад

Apache Tomcat Vulnerable to Improper Resource Shutdown or Release

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redos логотип
ROS-20251125-09

Множественные уязвимости tomcat11

CVSS3: 7.5
8 месяцев назад
redos логотип
ROS-20251125-08

Множественные уязвимости tomcat10

CVSS3: 7.5
8 месяцев назад
redos логотип
ROS-20251125-07

Множественные уязвимости tomcat

CVSS3: 7.5
8 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:01882-1

Security update for tomcat

4%
Низкий
около 1 года назад
github логотип
GHSA-ff77-26x5-69cr

Apache Tomcat Rewrite rule bypass

4%
Низкий
больше 1 года назад
fstec логотип
BDU:2025-05707

Уязвимость сервера приложений Apache Tomcat, связанная с недостатком механизма кодирования или экранирования выходных данных, позволяющая нарушителю оказать влияние на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 9.8
4%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:1537-1

Security update for tomcat10

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:1521-1

Security update for tomcat

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01537-1

Security update for tomcat10

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01521-1

Security update for tomcat

около 1 года назад
redos логотип
ROS-20250515-10

Множественные уязвимости tomcat

CVSS3: 9.8
около 1 года назад
ubuntu логотип
CVE-2025-61795

Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memory usage and application load, it was possible that space for the temporary copies of uploaded parts would be filled faster than GC cleared it, leading to a DoS. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.11, from 10.1.0-M1 through 10.1.46, from 9.0.0.M1 through 9.0.109. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.12 or later, 10.1.47 or later or 9.0.110 or later which fixes the issue.

CVSS3: 5.3
1%
Низкий
9 месяцев назад
redhat логотип
CVE-2025-61795

Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memory usage and application load, it was possible that space for the temporary copies of uploaded parts would be filled faster than GC cleared it, leading to a DoS. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.11, from 10.1.0-M1 through 10.1.46, from 9.0.0.M1 through 9.0.109. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.12 or later, 10.1.47 or later or 9.0.110 or later which fixes the issue.

CVSS3: 5.3
1%
Низкий
9 месяцев назад
nvd логотип
CVE-2025-61795

Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memory usage and application load, it was possible that space for the temporary copies of uploaded parts would be filled faster than GC cleared it, leading to a DoS. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.11, from 10.1.0-M1 through 10.1.46, from 9.0.0.M1 through 9.0.109. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.12 or later, 10.1.47 or later or 9.0.110 or later which fixes the issue.

CVSS3: 5.3
1%
Низкий
9 месяцев назад
debian логотип
CVE-2025-61795

Improper Resource Shutdown or Release vulnerability in Apache Tomcat. ...

CVSS3: 5.3
1%
Низкий
9 месяцев назад
ubuntu логотип
CVE-2025-55752

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Users are re...

CVSS3: 7.5
67%
Средний
9 месяцев назад
redhat логотип
CVE-2025-55752

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Users...

CVSS3: 7.5
67%
Средний
9 месяцев назад
nvd логотип
CVE-2025-55752

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Use

CVSS3: 7.5
67%
Средний
9 месяцев назад
debian логотип
CVE-2025-55752

Relative Path Traversal vulnerability in Apache Tomcat. The fix for b ...

CVSS3: 7.5
67%
Средний
9 месяцев назад
github логотип
GHSA-hgrr-935x-pq79

Apache Tomcat Vulnerable to Improper Resource Shutdown or Release

CVSS3: 5.3
1%
Низкий
9 месяцев назад

Уязвимостей на страницу