cbcvebase.

Apache Tomcat vulnerabilities

272 known vulnerabilities affecting apache/tomcat.

Total CVEs
272
CISA KEV
7
actively exploited
Public exploits
55
Exploited in wild
9
Severity breakdown
CRITICAL25HIGH90MEDIUM141LOW16

Vulnerabilities

Page 13 of 14
CVE-2009-0781P4MEDIUMCVSS 4.3v4.1.0v4.1.1+81 more2009-03-09
CVE-2009-0781 [MEDIUM] CWE-79 CVE-2009-0781: Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the exam Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."
nvd
CVE-2023-28708P4MEDIUMCVSS 4.3≥ 8.5.0, < 8.5.86fixed in 9.0.72+2 more2023-03-22
CVE-2023-28708 [MEDIUM] CWE-523 CVE-2023-28708: When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include t When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting th
nvd
CVE-2005-3510P4MEDIUMCVSS 5.0v5.5.0v5.5.1+10 more2005-11-06
CVE-2005-3510 [MEDIUM] CVE-2005-3510: Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.
nvd
CVE-2003-0043P4MEDIUMCVSS 5.0v3.0v3.1+7 more2003-02-07
CVE-2003-0043 [MEDIUM] CVE-2003-0043: Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when proc Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.
nvd
CVE-2007-1358P4LOWCVSS 2.6≤ 4.1.31v4.0.0+7 more2007-05-10
CVE-2007-1358 [LOW] CWE-79 CVE-2007-1358: Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4 Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".
nvd
CVE-2009-2696P4MEDIUMCVSS 4.3≤ 4.1.392010-08-05
CVE-2009-2696 [MEDIUM] CVE-2009-2696: Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the exam Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML." NOTE: this is due to a missing fix
nvd
CVE-2002-0935P4MEDIUMCVSS 5.0v4.0.32002-10-04
CVE-2002-0935 [MEDIUM] CVE-2002-0935: Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang.
nvd
CVE-2007-3383P4MEDIUMCVSS 4.3v4.0.0v4.0.1+15 more2007-07-25
CVE-2007-3383 [MEDIUM] CVE-2007-3383: Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (example Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject arbitrary web script or HTML via the From field and possibly other fields, related to generation of error messages.
nvd
CVE-2026-24733P4LOWCVSS 3.7≥ 9.0.1, < 9.0.113≥ 10.1.1, < 10.1.50+4 more2026-02-17
CVE-2026-24733 [LOW] CWE-20 CVE-2026-24733: Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests t Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apa
nvd
CVE-2001-0917P4MEDIUMCVSS 5.0v4.0.12001-11-22
CVE-2001-0917 [MEDIUM] CVE-2001-0917: Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a lon Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.
nvd
CVE-2009-0783P4MEDIUMCVSS 4.2≥ 4.1.0, ≤ 4.1.39≥ 5.5.0, ≤ 5.5.27+1 more2009-06-05
CVE-2009-0783 [MEDIUM] CWE-200 CVE-2009-0783: Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web appli Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the targe
nvd
CVE-2002-1895P4MEDIUMCVSS 5.0v3.3v4.0.42002-12-31
CVE-2002-1895 [MEDIUM] CVE-2002-1895: The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.
nvd
CVE-2006-7195P4MEDIUMCVSS 4.3v5.0.0v5.0.1+35 more2007-05-10
CVE-2006-7195 [MEDIUM] CVE-2006-7195: Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0. Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.
nvd
CVE-2005-3164P4LOWCVSS 2.6≥ 4.0.1, ≤ 4.0.6≥ 4.1.0, ≤ 4.1.362005-10-06
CVE-2005-3164 [LOW] CWE-200 CVE-2005-3164: The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request,
nvd
CVE-2007-4724P4MEDIUMCVSS 4.3v4.1.312007-09-05
CVE-2007-4724 [MEDIUM] CWE-352 CVE-2007-4724: Cross-site request forgery (CSRF) vulnerability in cal2.jsp in the calendar examples application in Cross-site request forgery (CSRF) vulnerability in cal2.jsp in the calendar examples application in Apache Tomcat 4.1.31 allows remote attackers to add events as arbitrary users via the time and description parameters.
nvd
CVE-2011-3376P4MEDIUMCVSS 4.4v7.0.0v7.0.1+20 more2011-11-11
CVE-2011-3376 [MEDIUM] CWE-264 CVE-2011-3376: org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not pro org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.
nvd
CVE-2026-43514P4LOWCVSS 3.7≥ 7.0.0, ≤ 7.0.109≥ 8.5.0, ≤ 8.5.100+3 more2026-05-12
CVE-2026-43514 [LOW] CWE-208 CVE-2026-43514: Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade
nvd
CVE-2002-2009P4MEDIUMCVSS 5.0v4.0.12002-12-31
CVE-2002-2009 [MEDIUM] CVE-2002-2009: Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP fi Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %20/, which leaks the pathname in an error message.
nvd
CVE-2013-2071P4LOWCVSS 2.6v7.0.0v7.0.1+26 more2013-06-01
CVE-2013-2071 [LOW] CWE-200 CVE-2013-2071: java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not prop java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that re
nvd
CVE-2011-2481P4MEDIUMCVSS 4.6v7.0.0v7.0.1+13 more2011-08-15
CVE-2011-2481 [MEDIUM] CVE-2011-2481: Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other w Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of
nvd
Apache Tomcat vulnerabilities | cvebase