Apache Tomcat vulnerabilities
272 known vulnerabilities affecting apache/tomcat.
Total CVEs
272
CISA KEV
7
actively exploited
Public exploits
55
Exploited in wild
9
Severity breakdown
CRITICAL25HIGH90MEDIUM141LOW16
Vulnerabilities
Page 10 of 14
CVE-2019-12418P3HIGHCVSS 7.0≥ 7.0.0, ≤ 7.0.97≥ 8.5.0, ≤ 8.5.47+1 more2019-12-23
CVE-2019-12418 [HIGH] CVE-2019-12418: When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacke
nvd
CVE-2012-5886P4MEDIUMCVSS 5.0v5.5.0v5.5.1+92 more2012-11-17
CVE-2012-5886 [MEDIUM] CWE-287 CVE-2012-5886: The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x befor
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.
nvd
CVE-2011-1183P4MEDIUMCVSS 5.8v7.0.112011-04-08
CVE-2011-1183 [MEDIUM] CVE-2011-1183: Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints,
Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
nvd
CVE-2008-0128P4MEDIUMCVSS 5.0≤ 5.5.202008-01-23
CVE-2008-0128 [MEDIUM] CWE-16 CVE-2008-0128: The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.
The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
nvd
CVE-2011-2729P4MEDIUMCVSS 5.0v5.5.32v5.5.33+21 more2011-08-15
CVE-2011-2729 [MEDIUM] CWE-264 CVE-2011-2729: native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons
native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.
nvd
CVE-2014-0119P4MEDIUMCVSS 4.3v8.0.0v8.0.1+91 more2014-05-31
CVE-2014-0119 [MEDIUM] CWE-264 CVE-2014-0119: Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the
Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, re
nvd
CVE-2011-5062P4MEDIUMCVSS 5.0v5.5.0v5.5.1+74 more2012-01-14
CVE-2011-5062 [MEDIUM] CVE-2011-5062: The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x befor
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.
nvd
CVE-2017-15706P4MEDIUMCVSS 5.3≥ 7.0.79, ≤ 7.0.82≥ 8.0.45, ≤ 8.0.47+3 more2018-01-31
CVE-2017-15706 [MEDIUM] CWE-358 CVE-2017-15706: As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to
As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify which script to execute. The update was not correct. As a result, some scripts may have failed to execute as expec
nvd
CVE-2002-1394P4HIGHCVSS 7.5v4.0.0v4.0.1+8 more2003-01-17
CVE-2002-1394 [HIGH] CVE-2002-1394: Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows
Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.
nvd
CVE-2007-5342P4MEDIUMCVSS 6.4v5.5.9v5.5.10+31 more2007-12-27
CVE-2007-5342 [MEDIUM] CWE-264 CVE-2007-5342: The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and
The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attrib
nvd
CVE-2022-23181P4HIGHCVSS 7.0≥ 8.5.55, ≤ 8.5.73≥ 9.0.35, ≤ 9.0.56+3 more2022-01-27
CVE-2022-23181 [HIGH] CVE-2022-23181: The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomc
The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to
nvd
CVE-2011-5063P4MEDIUMCVSS 4.3v5.5.0v5.5.1+74 more2012-01-14
CVE-2011-5063 [MEDIUM] CVE-2011-5063: The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x befor
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vul
nvd
CVE-2011-5064P4MEDIUMCVSS 4.3v5.5.0v5.5.1+74 more2012-01-14
CVE-2011-5064 [MEDIUM] CVE-2011-5064: DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.
DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a diffe
nvd
CVE-2024-52318P4MEDIUMCVSS 6.1v9.0.96v10.1.31+1 more2024-11-18
CVE-2024-52318 [MEDIUM] CWE-326 CVE-2024-52318: Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomc
Incorrect object recycling and reuse vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96.
Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue.
nvd
CVE-2005-2090P4MEDIUMCVSS 4.3v4.1.24v5.0.192005-07-05
CVE-2005-2090 [MEDIUM] CVE-2005-2090: Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison
Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Tomcat to incorrectly handle and forward the body of the request in a
nvd
CVE-2026-25854P4MEDIUMCVSS 6.1≥ 9.0.1, < 9.0.116≥ 10.1.0, < 10.1.53+2 more2026-04-09
CVE-2026-25854 [MEDIUM] CWE-601 CVE-2026-25854: Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via th
Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100.
Other, unsupported versions may also be affected
Users are re
nvd
CVE-2011-1475P4MEDIUMCVSS 5.0v7.0.0v7.0.1+10 more2011-04-08
CVE-2011-1475 [MEDIUM] CWE-20 CVE-2011-1475: The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining
The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."
nvd
CVE-2009-2901P4MEDIUMCVSS 4.3v5.5.0v5.5.1+49 more2010-01-28
CVE-2009-2901 [MEDIUM] CWE-264 CVE-2009-2901: The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when auto
The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.
nvd
CVE-2011-3375P4MEDIUMCVSS 5.0v6.0.30v6.0.31+24 more2012-01-19
CVE-2011-3375 [MEDIUM] CWE-200 CVE-2011-3375: Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching
Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
nvd
CVE-2016-0706P4MEDIUMCVSS 4.3v6.0.0v6.0.1+88 more2016-02-25
CVE-2016-0706 [MEDIUM] CWE-200 CVE-2016-0706: Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does
Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows remote authenticated users to bypass intended SecurityManager restrictions and read arbitrary HTTP requests, and c
nvd