cbcvebase.

Apache Tomcat vulnerabilities

261 known vulnerabilities affecting apache/tomcat.

Total CVEs
261
CISA KEV
6
actively exploited
Public exploits
55
Exploited in wild
8
Severity breakdown
CRITICAL21HIGH85MEDIUM139LOW16

Vulnerabilities

Page 11 of 14
CVE-2023-42794P4MEDIUMCVSS 5.9≥ 8.5.85, < 8.5.94≥ 9.0.70, < 9.0.812023-10-10
CVE-2023-42794 [MEDIUM] CWE-459 CVE-2023-42794: Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web application opened a stream for an uploaded file but failed to close the
nvd
CVE-2007-6286P4MEDIUMCVSS 4.3v5.5.11v5.5.12+29 more2008-02-12
CVE-2007-6286 [MEDIUM] CVE-2007-6286: Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.
nvd
CVE-2009-2902P4MEDIUMCVSS 4.3v5.5.0v5.5.1+49 more2010-01-28
CVE-2009-2902 [MEDIUM] CWE-22 CVE-2009-2902: Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 all Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to delete work-directory files via directory traversal sequences in a WAR filename, as demonstrated by the ...war filename.
nvd
CVE-2014-0095P4MEDIUMCVSS 5.0v8.0.0v8.0.1+1 more2014-05-31
CVE-2014-0095 [MEDIUM] CWE-20 CVE-2014-0095: java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.
nvd
CVE-2011-0534P4MEDIUMCVSS 5.0v7.0.0v7.0.1+32 more2011-02-10
CVE-2011-0534 [MEDIUM] CWE-399 CVE-2011-0534: Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize li Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.
nvd
CVE-2013-4590P4MEDIUMCVSS 4.3v8.0.0≤ 6.0.37+172 more2014-02-26
CVE-2013-4590 [MEDIUM] CWE-200 CVE-2013-4590: Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to a
nvd
CVE-2005-4836P4HIGHCVSS 7.8v4.1.15v4.1.16+23 more2005-12-31
CVE-2005-4836 [HIGH] CWE-200 CVE-2005-4836: The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL wh The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.
nvd
CVE-2011-1582P4MEDIUMCVSS 4.3v7.0.12v7.0.132011-05-20
CVE-2011-1582 [MEDIUM] CVE-2011-1582: Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
nvd
CVE-2000-0672P4MEDIUMCVSS 5.0v3.0v3.12000-07-20
CVE-2000-0672 [MEDIUM] CVE-2000-0672: The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which al The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory.
nvd
CVE-2012-0022P4MEDIUMCVSS 5.0v5.5.0v5.5.1+87 more2012-01-19
CVE-2012-0022 [MEDIUM] CVE-2012-0022: Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient appr Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.
nvd
CVE-2009-0033P4MEDIUMCVSS 5.0v4.1.0v4.1.1+83 more2009-06-05
CVE-2009-0033 [MEDIUM] CWE-20 CVE-2009-0033: Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJ Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to temporary blocking of connectors that have encountered errors, as demonstrate
nvd
CVE-2012-4431P4MEDIUMCVSS 4.3v6.0v6.0.0+57 more2012-12-19
CVE-2012-4431 [MEDIUM] CWE-264 CVE-2012-4431: org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x bef org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.
nvd
CVE-2010-4312P4MEDIUMCVSS 6.4v6.0v6.0.0+25 more2010-11-26
CVE-2010-4312 [MEDIUM] CWE-16 CVE-2010-4312: The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie he The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.
nvd
CVE-2012-5568P4MEDIUMCVSS 5.0≥ 7.0.0, ≤ 7.0.1052012-11-30
CVE-2012-5568 [MEDIUM] CVE-2012-5568: Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
nvd
CVE-2014-0033P4MEDIUMCVSS 4.3v6.0.33v6.0.34+3 more2014-02-26
CVE-2014-0033 [MEDIUM] CWE-20 CVE-2014-0033: org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not con org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not consider the disableURLRewriting setting when handling a session ID in a URL, which allows remote attackers to conduct session fixation attacks via a crafted URL.
nvd
CVE-2013-4322P4MEDIUMCVSS 4.3v7.0.0v7.0.1+172 more2014-02-26
CVE-2013-4322 [MEDIUM] CVE-2013-4322: Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a trailer field, which allows remote attackers to cause a denial of service by streaming data. NOTE: this vulnerability exists
nvd
CVE-2017-7674P4MEDIUMCVSS 4.3v7.0.41v7.0.42+98 more2017-08-11
CVE-2017-7674 [MEDIUM] CWE-345 CVE-2017-7674: The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0 The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances.
nvd
CVE-2005-0808P4MEDIUMCVSS 5.0v3.0v3.1+9 more2005-05-02
CVE-2005-0808 [MEDIUM] CVE-2005-0808: Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) vi Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.
nvd
CVE-2002-0493P4HIGHCVSS 7.5≤ 3.3.22002-08-12
CVE-2002-0493 [HIGH] CWE-254 CVE-2002-0493: Apache Tomcat may be started without proper security settings if errors are encountered while readin Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.
nvd
CVE-2003-0044P4MEDIUMCVSS 6.8v3.0v3.1+8 more2003-02-07
CVE-2003-0044 [MEDIUM] CVE-2003-0044: Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web application Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.
nvd
Apache Tomcat vulnerabilities | cvebase