Количество 1 533
Количество 1 533
SUSE-SU-2019:1825-1
Security update for tomcat
SUSE-SU-2015:1281-1
Security update for tomcat
RLSA-2025:7494
Moderate: tomcat9 security update
RLSA-2024:0539
Important: tomcat security update
GHSA-xmf4-j3j7-xj7q
Apache Tomcat DoS Via Requests Including Null Characters
GHSA-xmc9-6p56-3c4v
Apache Tomcat XSS In Accept-Language Headers
GHSA-xh5x-j8jf-pcpx
Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Tomcat
GHSA-xcpr-7mr4-h4xq
Apache Tomcat - Authentication Bypass
GHSA-x89r-2wjq-mj7x
Apache Tomcat Discloses MS-DOS Pathname
GHSA-x75h-2jg7-ffxw
Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML." NOTE: this is due to a missing fix for CVE-2009-0781.
GHSA-x4m4-345f-5h5g
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
GHSA-x445-mmpw-7r4f
Apache Tomcat Allows Source Disclosure
GHSA-wrvx-pxxf-g8fg
Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
GHSA-wr62-c79q-cv37
Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits
GHSA-wr3m-gw98-mc3j
Improper Input Validation in Apache Tomcat
GHSA-wq2p-q66w-q8gp
Apache Tomcat Denial of Service vulnerability
GHSA-wmwf-9ccg-fff5
Apache Tomcat Vulnerable to Relative Path Traversal
GHSA-wjwr-3jch-479j
Apache Tomcat SendMailServlet XSS
GHSA-wfvx-wr33-m97w
The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u8 on Debian wheezy, before 7.0.56-3+deb8u6 on Debian jessie, before 7.0.52-1ubuntu0.8 on Ubuntu 14.04 LTS, and on Ubuntu 12.04 LTS, 16.04 LTS, and 16.10; and the tomcat8 package before 8.0.14-1+deb8u5 on Debian jessie, before 8.0.32-1ubuntu1.3 on Ubuntu 16.04 LTS, before 8.0.37-1ubuntu0.1 on Ubuntu 16.10, and before 8.0.38-2ubuntu1 on Ubuntu 17.04 might allow local users with access to the tomcat account to obtain sensitive information or gain root privileges via a symlink attack on the Catalina localhost directory.
GHSA-wfj7-mhr5-pcwq
Apache Tomcat Reveals Directories
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
SUSE-SU-2019:1825-1 Security update for tomcat | 73% Высокий | около 7 лет назад | ||
SUSE-SU-2015:1281-1 Security update for tomcat | 14% Средний | около 11 лет назад | ||
RLSA-2025:7494 Moderate: tomcat9 security update | 100% Критический | 12 месяцев назад | ||
RLSA-2024:0539 Important: tomcat security update | 3% Низкий | больше 2 лет назад | ||
GHSA-xmf4-j3j7-xj7q Apache Tomcat DoS Via Requests Including Null Characters | 8% Низкий | больше 4 лет назад | ||
GHSA-xmc9-6p56-3c4v Apache Tomcat XSS In Accept-Language Headers | 20% Средний | больше 4 лет назад | ||
GHSA-xh5x-j8jf-pcpx Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Tomcat | 9% Низкий | больше 4 лет назад | ||
GHSA-xcpr-7mr4-h4xq Apache Tomcat - Authentication Bypass | CVSS3: 9.8 | 6% Низкий | почти 2 года назад | |
GHSA-x89r-2wjq-mj7x Apache Tomcat Discloses MS-DOS Pathname | 26% Средний | больше 4 лет назад | ||
GHSA-x75h-2jg7-ffxw Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML." NOTE: this is due to a missing fix for CVE-2009-0781. | 5% Низкий | больше 4 лет назад | ||
GHSA-x4m4-345f-5h5g Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
GHSA-x445-mmpw-7r4f Apache Tomcat Allows Source Disclosure | 11% Средний | больше 4 лет назад | ||
GHSA-wrvx-pxxf-g8fg Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue. | CVSS3: 6.8 | 1% Низкий | 19 дней назад | |
GHSA-wr62-c79q-cv37 Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits | CVSS3: 7.5 | 2% Низкий | около 1 года назад | |
GHSA-wr3m-gw98-mc3j Improper Input Validation in Apache Tomcat | 80% Высокий | больше 4 лет назад | ||
GHSA-wq2p-q66w-q8gp Apache Tomcat Denial of Service vulnerability | 9% Низкий | больше 4 лет назад | ||
GHSA-wmwf-9ccg-fff5 Apache Tomcat Vulnerable to Relative Path Traversal | CVSS3: 7.5 | 67% Средний | 11 месяцев назад | |
GHSA-wjwr-3jch-479j Apache Tomcat SendMailServlet XSS | 9% Низкий | больше 4 лет назад | ||
GHSA-wfvx-wr33-m97w The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u8 on Debian wheezy, before 7.0.56-3+deb8u6 on Debian jessie, before 7.0.52-1ubuntu0.8 on Ubuntu 14.04 LTS, and on Ubuntu 12.04 LTS, 16.04 LTS, and 16.10; and the tomcat8 package before 8.0.14-1+deb8u5 on Debian jessie, before 8.0.32-1ubuntu1.3 on Ubuntu 16.04 LTS, before 8.0.37-1ubuntu0.1 on Ubuntu 16.10, and before 8.0.38-2ubuntu1 on Ubuntu 17.04 might allow local users with access to the tomcat account to obtain sensitive information or gain root privileges via a symlink attack on the Catalina localhost directory. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-wfj7-mhr5-pcwq Apache Tomcat Reveals Directories | 46% Средний | больше 4 лет назад |
Уязвимостей на страницу