Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 37

Количество 37

rocky логотип

RLSA-2025:23052

8 месяцев назад

Important: tomcat9 security update

EPSS: Низкий
rocky логотип

RLSA-2025:23049

8 месяцев назад

Important: tomcat security update

EPSS: Низкий
rocky логотип

RLSA-2025:23048

8 месяцев назад

Important: tomcat security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-23052

8 месяцев назад

ELSA-2025-23052: tomcat9 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-23049

8 месяцев назад

ELSA-2025-23049: tomcat security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-23048

8 месяцев назад

ELSA-2025-23048: tomcat security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2025:23050

8 месяцев назад

Important: tomcat security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-23050

8 месяцев назад

ELSA-2025-23050: tomcat security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2025-31651

больше 1 года назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2025-31651

больше 1 года назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-31651

больше 1 года назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2025-31651

больше 1 года назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerab ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2025-55752

9 месяцев назад

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Users are re...

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2025-55752

9 месяцев назад

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Users...

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2025-55752

9 месяцев назад

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Use

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2025-55752

9 месяцев назад

Relative Path Traversal vulnerability in Apache Tomcat. The fix for b ...

CVSS3: 7.5
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2025:01882-1

около 1 года назад

Security update for tomcat

EPSS: Низкий
github логотип

GHSA-ff77-26x5-69cr

больше 1 года назад

Apache Tomcat Rewrite rule bypass

EPSS: Низкий
fstec логотип

BDU:2025-05707

больше 1 года назад

Уязвимость сервера приложений Apache Tomcat, связанная с недостатком механизма кодирования или экранирования выходных данных, позволяющая нарушителю оказать влияние на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-wmwf-9ccg-fff5

9 месяцев назад

Apache Tomcat Vulnerable to Relative Path Traversal

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2025:23052

Important: tomcat9 security update

8 месяцев назад
rocky логотип
RLSA-2025:23049

Important: tomcat security update

8 месяцев назад
rocky логотип
RLSA-2025:23048

Important: tomcat security update

8 месяцев назад
oracle-oval логотип
ELSA-2025-23052

ELSA-2025-23052: tomcat9 security update (IMPORTANT)

8 месяцев назад
oracle-oval логотип
ELSA-2025-23049

ELSA-2025-23049: tomcat security update (IMPORTANT)

8 месяцев назад
oracle-oval логотип
ELSA-2025-23048

ELSA-2025-23048: tomcat security update (IMPORTANT)

8 месяцев назад
rocky логотип
RLSA-2025:23050

Important: tomcat security update

8 месяцев назад
oracle-oval логотип
ELSA-2025-23050

ELSA-2025-23050: tomcat security update (IMPORTANT)

8 месяцев назад
ubuntu логотип
CVE-2025-31651

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

CVSS3: 9.8
4%
Низкий
больше 1 года назад
redhat логотип
CVE-2025-31651

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

CVSS3: 5.3
4%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-31651

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

CVSS3: 9.8
4%
Низкий
больше 1 года назад
debian логотип
CVE-2025-31651

Improper Neutralization of Escape, Meta, or Control Sequences vulnerab ...

CVSS3: 9.8
4%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-55752

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Users are re...

CVSS3: 7.5
67%
Средний
9 месяцев назад
redhat логотип
CVE-2025-55752

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Users...

CVSS3: 7.5
67%
Средний
9 месяцев назад
nvd логотип
CVE-2025-55752

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Use

CVSS3: 7.5
67%
Средний
9 месяцев назад
debian логотип
CVE-2025-55752

Relative Path Traversal vulnerability in Apache Tomcat. The fix for b ...

CVSS3: 7.5
67%
Средний
9 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:01882-1

Security update for tomcat

4%
Низкий
около 1 года назад
github логотип
GHSA-ff77-26x5-69cr

Apache Tomcat Rewrite rule bypass

4%
Низкий
больше 1 года назад
fstec логотип
BDU:2025-05707

Уязвимость сервера приложений Apache Tomcat, связанная с недостатком механизма кодирования или экранирования выходных данных, позволяющая нарушителю оказать влияние на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 9.8
4%
Низкий
больше 1 года назад
github логотип
GHSA-wmwf-9ccg-fff5

Apache Tomcat Vulnerable to Relative Path Traversal

CVSS3: 7.5
67%
Средний
9 месяцев назад

Уязвимостей на страницу