cbcvebase.

Apache Tomcat vulnerabilities

272 known vulnerabilities affecting apache/tomcat.

Total CVEs
272
CISA KEV
7
actively exploited
Public exploits
55
Exploited in wild
9
Severity breakdown
CRITICAL25HIGH90MEDIUM141LOW16

Vulnerabilities

Page 12 of 14
CVE-2012-0022P4MEDIUMCVSS 5.0v5.5.0v5.5.1+87 more2012-01-19
CVE-2012-0022 [MEDIUM] CVE-2012-0022: Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient appr Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.
nvd
CVE-2009-0033P4MEDIUMCVSS 5.0v4.1.0v4.1.1+83 more2009-06-05
CVE-2009-0033 [MEDIUM] CWE-20 CVE-2009-0033: Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJ Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to temporary blocking of connectors that have encountered errors, as demonstrate
nvd
CVE-2012-4431P4MEDIUMCVSS 4.3v6.0v6.0.0+57 more2012-12-19
CVE-2012-4431 [MEDIUM] CWE-264 CVE-2012-4431: org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x bef org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.
nvd
CVE-2010-4312P4MEDIUMCVSS 6.4v6.0v6.0.0+25 more2010-11-26
CVE-2010-4312 [MEDIUM] CWE-16 CVE-2010-4312: The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie he The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.
nvd
CVE-2012-5568P4MEDIUMCVSS 5.0≥ 7.0.0, ≤ 7.0.1052012-11-30
CVE-2012-5568 [MEDIUM] CVE-2012-5568: Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
nvd
CVE-2014-0033P4MEDIUMCVSS 4.3v6.0.33v6.0.34+3 more2014-02-26
CVE-2014-0033 [MEDIUM] CWE-20 CVE-2014-0033: org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not con org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not consider the disableURLRewriting setting when handling a session ID in a URL, which allows remote attackers to conduct session fixation attacks via a crafted URL.
nvd
CVE-2013-4322P4MEDIUMCVSS 4.3v7.0.0v7.0.1+172 more2014-02-26
CVE-2013-4322 [MEDIUM] CVE-2013-4322: Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a trailer field, which allows remote attackers to cause a denial of service by streaming data. NOTE: this vulnerability exists
nvd
CVE-2017-7674P4MEDIUMCVSS 4.3v7.0.41v7.0.42+98 more2017-08-11
CVE-2017-7674 [MEDIUM] CWE-345 CVE-2017-7674: The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0 The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances.
nvd
CVE-2005-0808P4MEDIUMCVSS 5.0v3.0v3.1+9 more2005-05-02
CVE-2005-0808 [MEDIUM] CVE-2005-0808: Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) vi Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.
nvd
CVE-2002-0493P4HIGHCVSS 7.5≤ 3.3.22002-08-12
CVE-2002-0493 [HIGH] CWE-254 CVE-2002-0493: Apache Tomcat may be started without proper security settings if errors are encountered while readin Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.
nvd
CVE-2003-0044P4MEDIUMCVSS 6.8v3.0v3.1+8 more2003-02-07
CVE-2003-0044 [MEDIUM] CVE-2003-0044: Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web application Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.
nvd
CVE-2008-0002P4MEDIUMCVSS 5.8v6.0.5v6.0.6+9 more2008-02-12
CVE-2008-0002 [MEDIUM] CVE-2008-0002: Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.
nvd
CVE-2008-3271P4MEDIUMCVSS 4.3v4.1.0v4.1.1+31 more2008-10-13
CVE-2008-3271 [MEDIUM] CWE-264 CVE-2008-3271: Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restric Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and relat
nvd
CVE-2011-0013P4MEDIUMCVSS 4.3v7.0.0v7.0.1+63 more2011-02-19
CVE-2011-0013 [MEDIUM] CWE-79 CVE-2011-0013: Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5 Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.
nvd
CVE-2001-1563P4HIGHCVSS 7.5v3.2.12001-12-31
CVE-2001-1563 [HIGH] CVE-2001-1563: Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to acce Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers.
nvd
CVE-2008-5519P4LOWCVSS 2.6v4.0.0v4.0.1+100 more2009-04-09
CVE-2008-5519 [LOW] CWE-200 CVE-2008-5519: The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtai The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from a different client that included a Content-Length header but no POST data or (2) a rapid series of requests, related to noncom
nvd
CVE-2007-1858P4LOWCVSS 2.6v4.1.28v4.1.31+41 more2007-05-10
CVE-2007-1858 [LOW] CVE-2007-1858: The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, a The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.
nvd
CVE-2005-4838P4MEDIUMCVSS 4.3≤ 5.5.62005-12-31
CVE-2005-4838 [MEDIUM] CWE-79 CVE-2005-4838: Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomc Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomcat 5.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) el/functions.jsp, (2) el/implicit-objects.jsp, and (3) jspx/textRotate.jspx in examples/jsp2/, as demonstrated via script in a request to snp/snoop.jsp. NOTE: othe
nvd
CVE-2000-1210P4MEDIUMCVSS 5.0≤ 3.12002-03-22
CVE-2000-1210 [MEDIUM] CVE-2000-1210: Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.
nvd
CVE-2008-1947P4MEDIUMCVSS 4.3v5.5.9v5.5.10+33 more2008-06-04
CVE-2008-1947 [MEDIUM] CWE-79 CVE-2008-1947: Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0 Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.
nvd
Apache Tomcat vulnerabilities | cvebase