cbcvebase.

Apache Tomcat vulnerabilities

261 known vulnerabilities affecting apache/tomcat.

Total CVEs
261
CISA KEV
6
actively exploited
Public exploits
55
Exploited in wild
8
Severity breakdown
CRITICAL21HIGH85MEDIUM139LOW16

Vulnerabilities

Page 12 of 14
CVE-2008-0002P4MEDIUMCVSS 5.8v6.0.5v6.0.6+9 more2008-02-12
CVE-2008-0002 [MEDIUM] CVE-2008-0002: Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.
nvd
CVE-2008-3271P4MEDIUMCVSS 4.3v4.1.0v4.1.1+31 more2008-10-13
CVE-2008-3271 [MEDIUM] CWE-264 CVE-2008-3271: Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restric Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and relat
nvd
CVE-2011-0013P4MEDIUMCVSS 4.3v7.0.0v7.0.1+63 more2011-02-19
CVE-2011-0013 [MEDIUM] CWE-79 CVE-2011-0013: Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5 Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.
nvd
CVE-2001-1563P4HIGHCVSS 7.5v3.2.12001-12-31
CVE-2001-1563 [HIGH] CVE-2001-1563: Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to acce Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers.
nvd
CVE-2008-5519P4LOWCVSS 2.6v4.0.0v4.0.1+100 more2009-04-09
CVE-2008-5519 [LOW] CWE-200 CVE-2008-5519: The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtai The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from a different client that included a Content-Length header but no POST data or (2) a rapid series of requests, related to noncom
nvd
CVE-2000-1210P4MEDIUMCVSS 5.0≤ 3.12002-03-22
CVE-2000-1210 [MEDIUM] CVE-2000-1210: Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.
nvd
CVE-2008-1947P4MEDIUMCVSS 4.3v5.5.9v5.5.10+33 more2008-06-04
CVE-2008-1947 [MEDIUM] CWE-79 CVE-2008-1947: Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0 Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.
nvd
CVE-2009-0781P4MEDIUMCVSS 4.3v4.1.0v4.1.1+81 more2009-03-09
CVE-2009-0781 [MEDIUM] CWE-79 CVE-2009-0781: Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the exam Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."
nvd
CVE-2007-1858P4LOWCVSS 2.6v4.1.28v4.1.31+41 more2007-05-10
CVE-2007-1858 [LOW] CVE-2007-1858: The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, a The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.
nvd
CVE-2005-4838P4MEDIUMCVSS 4.3≤ 5.5.62005-12-31
CVE-2005-4838 [MEDIUM] CWE-79 CVE-2005-4838: Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomc Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomcat 5.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) el/functions.jsp, (2) el/implicit-objects.jsp, and (3) jspx/textRotate.jspx in examples/jsp2/, as demonstrated via script in a request to snp/snoop.jsp. NOTE: othe
nvd
CVE-2023-28708P4MEDIUMCVSS 4.3≥ 8.5.0, < 8.5.86fixed in 9.0.72+2 more2023-03-22
CVE-2023-28708 [MEDIUM] CWE-523 CVE-2023-28708: When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include t When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting th
nvd
CVE-2005-3510P4MEDIUMCVSS 5.0v5.5.0v5.5.1+10 more2005-11-06
CVE-2005-3510 [MEDIUM] CVE-2005-3510: Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.
nvd
CVE-2007-1358P4LOWCVSS 2.6≤ 4.1.31v4.0.0+7 more2007-05-10
CVE-2007-1358 [LOW] CWE-79 CVE-2007-1358: Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4 Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".
nvd
CVE-2003-0043P4MEDIUMCVSS 5.0v3.0v3.1+7 more2003-02-07
CVE-2003-0043 [MEDIUM] CVE-2003-0043: Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when proc Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.
nvd
CVE-2009-2696P4MEDIUMCVSS 4.3≤ 4.1.392010-08-05
CVE-2009-2696 [MEDIUM] CVE-2009-2696: Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the exam Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML." NOTE: this is due to a missing fix
nvd
CVE-2002-0935P4MEDIUMCVSS 5.0v4.0.32002-10-04
CVE-2002-0935 [MEDIUM] CVE-2002-0935: Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang.
nvd
CVE-2007-3383P4MEDIUMCVSS 4.3v4.0.0v4.0.1+15 more2007-07-25
CVE-2007-3383 [MEDIUM] CVE-2007-3383: Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (example Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject arbitrary web script or HTML via the From field and possibly other fields, related to generation of error messages.
nvd
CVE-2026-24733P4LOWCVSS 3.7≥ 9.0.1, < 9.0.113≥ 10.1.1, < 10.1.50+4 more2026-02-17
CVE-2026-24733 [LOW] CWE-20 CVE-2026-24733: Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests t Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apa
nvd
CVE-2001-0917P4MEDIUMCVSS 5.0v4.0.12001-11-22
CVE-2001-0917 [MEDIUM] CVE-2001-0917: Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a lon Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.
nvd
CVE-2009-0783P4MEDIUMCVSS 4.2≥ 4.1.0, ≤ 4.1.39≥ 5.5.0, ≤ 5.5.27+1 more2009-06-05
CVE-2009-0783 [MEDIUM] CWE-200 CVE-2009-0783: Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web appli Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the targe
nvd
Apache Tomcat vulnerabilities | cvebase