Package impact

java Maven / org.apache.tomcat:tomcat

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2009-3555 critical 9.8 10.0 17y ago The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9… debianubuntufedorajava+2
CVE-2026-43512 critical 9.8 9.8 15d ago Apache Tomcat - Digest authenticator will authenticate any unknown user susedebianjavaapache
CVE-2026-41293 critical 9.8 9.8 15d ago Apache Tomcat - HTTP/2 request headers not validated susedebianjavaapache
CVE-2025-55754 critical 9.6 9.6 9d ago Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences redhatsusedebianjava+1
CVE-2026-29145 critical 9.5 2mo ago Apache Tomcat: CLIENT_CERT authentication does not fail as expected susedebianjava
CVE-2026-43515 critical 9.1 9.1 15d ago Apache Tomcat - Security constraints not correctly applied susedebianjavaapache
CVE-2016-0714 high 8.8 8.8 10y ago The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticat… debianubuntujavaapache
CVE-2015-5351 high 8.8 8.8 10y ago The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, wh… susedebianubuntujava+1
CVE-2015-5346 high 8.1 8.1 10y ago Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the sam… susedebianubuntujava+1
CVE-2026-29129 high 8.0 2mo ago Apache Tomcat: Configured cipher preference order not preserved susedebianjava
CVE-2021-42340 high 8.0 4y ago The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics f… redhatarchdebianjava
CVE-2020-13935 high 8.0 4y ago The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could t… archsusedebianjava
CVE-2020-13934 high 8.0 4y ago Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat archsusedebianjava
CVE-2014-0230 high 7.8 11y ago Uncontrolled Resource Consumption in Apache Tomcat javaapache
CVE-2026-43513 high 7.5 7.5 15d ago Apache Tomcat: LockOutRealm treats user names as case-sensitive susedebianjavaapache
CVE-2026-41284 high 7.5 7.5 15d ago Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling susedebianjavaapache
CVE-2026-34486 high 7.5 7.5 2mo ago Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.5… susedebianjavaapache
CVE-2025-55752 high 7.5 7.5 6mo ago Important: tomcat security update rockylinuxredhatsusedebian+2
CVE-2017-7675 high 7.5 7.5 9y ago The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. It was therefore possible to bypa… susedebianjavaapache
CVE-2016-6796 high 7.5 7.5 9y ago Apache Tomcat vulnerable to SecurityManager bypass susedebianredhatubuntu+2
CVE-2016-6817 high 7.5 7.5 9y ago The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of s… debianjavaapache
CVE-2016-6797 high 7.5 7.5 9y ago Incorrect Authorization in Apache Tomcat susedebianredhatubuntu+2
CVE-2017-5664 high 7.5 7.5 9y ago The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is configured for the error that occurred, the original request and response are forwa… susedebianjavaapache
CVE-2017-5650 high 7.5 7.5 9y ago In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated with that connection that were currently waiting f… debianjavaapache
CVE-2017-5647 high 7.5 7.5 9y ago A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in… susedebianjavaapache
CVE-2014-0050 high 7.5 12y ago Commons FileUpload Denial of service vulnerability debianjavaapache
CVE-2013-2185 high 7.5 13y ago Deserialization of Untrusted Data in Apache Tomcat javaapache
CVE-2011-3190 high 7.5 15y ago Apache Tomcat Allows Remote Attackers to Spoof AJP Requests javaapache
CVE-2026-42498 high 7.3 7.3 15d ago Apache Tomcat - WebSocket authentication header exposure susedebianjavaapache
CVE-2013-4444 medium 6.8 12y ago Apache Tomcat Unrestricted file upload vulnerability susejavaapache
CVE-2013-2067 medium 6.8 13y ago Improper Authentication in Apache Tomcat javaapache
CVE-2014-0227 medium 6.4 11y ago Improper Input Validation in Apache Tomcat javaapache
CVE-2010-4312 medium 6.4 16y ago Apache Tomcat has cookies without HTTPOnly flag in Set-Cookie header javaapache
CVE-2010-2227 medium 6.4 16y ago Apache Tomcat does not properly handle an invalid Transfer-Encoding header javaapache
CVE-2016-0763 medium 6.3 6.3 10y ago The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLink… debianubuntujavaapache
CVE-2016-0762 medium 5.9 5.9 9y ago Observable Discrepancy in Apache Tomcat susedebianredhatubuntu+2
CVE-2013-4286 medium 5.8 12y ago Apache Tomcat is vulnerable to HTTP request-smuggling javaapache
CVE-2011-1183 medium 5.8 15y ago Access controll bypass in Apache Tomcat javaapache
CVE-2011-1419 medium 5.8 15y ago Apache Tomcat does not follow ServletSecurity annotations javaapache
CVE-2011-1088 medium 5.8 15y ago Apache Tomcat allows remote attackers to bypass intended access restrictions javaapache
CVE-2009-2693 medium 5.8 17y ago Apache Tomcat Directory Traversal vulnerability javaapache
CVE-2023-45648 medium 5.5 2y ago Moderate: tomcat security update redhatsusedebianjava
CVE-2023-42795 medium 5.5 2y ago Moderate: tomcat security update redhatsusedebianjava
CVE-2023-41080 medium 5.5 2y ago Moderate: tomcat security update redhatsusedebianjava
CVE-2022-25762 medium 5.5 4y ago If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible tha… suserockylinuxdebianjava
CVE-2020-11996 medium 5.5 4y ago A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient … archsusedebianjava
CVE-2020-1935 medium 5.5 6y ago In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as va… rockylinuxdebianjava
CVE-2025-61795 medium 5.3 5.3 7mo ago Apache Tomcat Vulnerable to Improper Resource Shutdown or Release susedebianjavaapache
CVE-2016-6794 medium 5.3 5.3 9y ago System Property Disclosure in Apache Tomcat susedebianredhatubuntu+2
CVE-2015-5345 medium 5.3 5.3 10y ago The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which a… susedebianubuntujava+1
CVE-2014-7810 medium 5.0 11y ago Improper Access Control in Apache Tomcat debianjavaapache
CVE-2014-0075 medium 5.0 12y ago Integer Overflow or Wraparound in Apache Tomcat javaapache
CVE-2012-3544 medium 5.0 13y ago Apache Tomcat Vulnerable to Denial of Service (DoS) via Improper Handling of chunk extensions susejavaapache
CVE-2012-5885 medium 5.0 14y ago Improper Access Control in Apache Tomcat javaapache
CVE-2012-0022 medium 5.0 15y ago Denial of Service in Apache Tomcat javaapache
CVE-2011-3375 medium 5.0 15y ago Apache Tomcat Exposes IP Addresses and HTTP Headers of Requests javaapache
CVE-2011-5062 medium 5.0 15y ago Improper Authentication in Apache Tomcat javaapache
CVE-2011-1184 medium 5.0 15y ago Authentication Bypass in Apache Tomcat javaapache
CVE-2011-4858 medium 5.0 15y ago Improper Input Validation in Apache Tomcat javaapache
CVE-2011-1475 medium 5.0 15y ago Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users javaapache
CVE-2010-4476 medium 5.0 16y ago Apache Tomcat affected by infinite loop in Double.parseDouble method in Java Runtime Environment java
CVE-2011-0534 medium 5.0 16y ago Apache Tomcat does not enforce the maxHttpHeaderSize limit javaapache
CVE-2011-2481 medium 4.6 15y ago Apache Tomcat Allows Replacing of XML Parser javaapache
CVE-2011-2526 medium 4.4 15y ago Improper Input Validation in Apache Tomcat javaapache
CVE-2017-7674 medium 4.3 4.3 9y ago The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Orig… susedebianjavaapache
CVE-2016-0706 medium 4.3 4.3 10y ago Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/Restrict… susedebianubuntujava+1
CVE-2015-5174 medium 4.3 4.3 10y ago Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat susedebianubuntujava+1
CVE-2014-0119 medium 4.3 12y ago Missing XML Validation in Apache Tomcat susejavaapache
CVE-2014-0099 medium 4.3 12y ago Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Tomcat susejavaapache
CVE-2014-0096 medium 4.3 12y ago Improper Input Validation in Apache Tomcat javaapache
CVE-2014-0033 medium 4.3 12y ago Improper Input Validation in Apache Tomcat javaapache
CVE-2013-4590 medium 4.3 12y ago Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat debianjavaapache
CVE-2013-4322 medium 4.3 12y ago Apache Tomcat Denial of Service vulnerability javaapache
CVE-2012-4431 medium 4.3 14y ago Cross-Site Request Forgery in Apache Tomcat javaapache
CVE-2012-3546 medium 4.3 14y ago Authentication Bypass in Apache Tomcat javaapache
CVE-2011-5064 medium 4.3 15y ago Use of Hard-coded Cryptographic Key in Apache Tomcat javaapache
CVE-2011-5063 medium 4.3 15y ago Improper Authentication in Apache Tomcat javaapache
CVE-2011-1582 medium 4.3 15y ago Access restriction bypass in Apache Tomcat javaapache
CVE-2011-0013 medium 4.3 16y ago Improper Neutralization of Input During Web Page Generation in Apache Tomcat javaapache
CVE-2010-4172 medium 4.3 16y ago Improper Neutralization of Input During Web Page Generation in Apache Tomcat javaapache
CVE-2009-2902 medium 4.3 17y ago Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Apache Tomcat javaapache
CVE-2009-2901 medium 4.3 17y ago Improper Authentication in Apache Tomcat javaapache
CVE-2026-43514 low 3.7 3.7 15d ago Apache Tomcat - AJP secret compared in non-constant time susedebianjavaapache
CVE-2013-2071 low 2.6 13y ago Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat javaapache
CVE-2010-1157 low 2.6 16y ago Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat javaapache
CVE-2024-54677 low 2.5 2y ago Apache Tomcat Uncontrolled Resource Consumption vulnerability susedebianjava
CVE-2011-2204 low 1.9 15y ago Insertion of Sensitive Information into Log File in Apache Tomcat javaapache
CVE-2010-3718 low 1.2 16y ago Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat javaapache
CVE-2026-34487 unknown 2mo ago Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat… susedebianjavagcp
CVE-2026-34483 unknown 2mo ago Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 1… susedebianjava
CVE-2026-32990 unknown 2mo ago Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, fro… debianjava
CVE-2026-29146 unknown 2mo ago Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from … susedebianjavagcp
CVE-2026-25854 unknown 2mo ago Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, fro… susedebianjava
CVE-2026-24733 unknown 3mo ago Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny… susedebianjava
CVE-2025-66614 unknown 3mo ago Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were… susedebianjava
CVE-2025-49124 unknown 1y ago Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects A… susedebianjava
CVE-2021-43980 unknown 4y ago The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in … susedebianjava
CVE-2022-34305 unknown 4y ago In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data with… susedebianjava
CVE-2012-5887 unknown 4y ago Improper Authentication in Apache Tomcat java
CVE-2008-5515 unknown 4y ago Directory Traversal in Apache Tomcat java