CVE-2014-0033

medium
Published 2014-02-26 · Modified 2023-11-08
CVSS v3
CVSS v2
4.3
VIR risk
4.3

Description

Improper Input Validation in Apache Tomcat

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://tomcat.apache.org/security-6.html

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.apache.tomcat:tomcat>=6.0.33,<6.0.386.0.38

Application impact

VendorProductVersionsFixed
apache apachetomcat6.0.33
apache apachetomcat6.0.34
apache apachetomcat6.0.35
apache apachetomcat6.0.36
apache apachetomcat6.0.37

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.