Skip to main content

Vendor/product archive

apache / tomcat CVEs

Beta · best-effort

264 CVEs tagged to apache / tomcat21 Critical, 86 High, 141 Medium, 16 Low, 0 Unrated.

CVE-2024-38286

Published Nov 7, 2024

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 1…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-34750

Published Jul 3, 2024

Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases o…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-21733

Published Jan 19, 2024

Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46589

Published Nov 28, 2023

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 thro…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45648

Published Oct 10, 2023

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 thro…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42795

Published Oct 10, 2023

Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42794

Published Oct 10, 2023

Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41080

Published Aug 25, 2023

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10,…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34981

Published Jun 21, 2023

A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28708

Published Mar 22, 2023

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45143

Published Jan 3, 2023

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42252

Published Nov 1, 2022

If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43980

Published Sep 28, 2022

The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger)…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-34305

Published Jun 23, 2022

In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed use…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25762

Published May 13, 2022

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23181

Published Jan 27, 2022

The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to…

CVSS 7.0 · High

CVE-2021-30640

Published Jul 12, 2021

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the…

CVSS 6.5 · Medium
Showing 51-75 of 264 CVEsPage 3 of 11