cbcvebase.

Apache Tomcat vulnerabilities

261 known vulnerabilities affecting apache/tomcat.

Total CVEs
261
CISA KEV
6
actively exploited
Public exploits
55
Exploited in wild
8
Severity breakdown
CRITICAL21HIGH85MEDIUM139LOW16

Vulnerabilities

Page 13 of 14
CVE-2002-1895P4MEDIUMCVSS 5.0v3.3v4.0.42002-12-31
CVE-2002-1895 [MEDIUM] CVE-2002-1895: The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.
nvd
CVE-2006-7195P4MEDIUMCVSS 4.3v5.0.0v5.0.1+35 more2007-05-10
CVE-2006-7195 [MEDIUM] CVE-2006-7195: Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0. Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.
nvd
CVE-2007-4724P4MEDIUMCVSS 4.3v4.1.312007-09-05
CVE-2007-4724 [MEDIUM] CWE-352 CVE-2007-4724: Cross-site request forgery (CSRF) vulnerability in cal2.jsp in the calendar examples application in Cross-site request forgery (CSRF) vulnerability in cal2.jsp in the calendar examples application in Apache Tomcat 4.1.31 allows remote attackers to add events as arbitrary users via the time and description parameters.
nvd
CVE-2011-3376P4MEDIUMCVSS 4.4v7.0.0v7.0.1+20 more2011-11-11
CVE-2011-3376 [MEDIUM] CWE-264 CVE-2011-3376: org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not pro org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.
nvd
CVE-2026-43514P4LOWCVSS 3.7≥ 7.0.0, ≤ 7.0.109≥ 8.5.0, ≤ 8.5.100+3 more2026-05-12
CVE-2026-43514 [LOW] CWE-208 CVE-2026-43514: Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade
nvd
CVE-2002-2009P4MEDIUMCVSS 5.0v4.0.12002-12-31
CVE-2002-2009 [MEDIUM] CVE-2002-2009: Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP fi Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %20/, which leaks the pathname in an error message.
nvd
CVE-2005-3164P4LOWCVSS 2.6≥ 4.0.1, ≤ 4.0.6≥ 4.1.0, ≤ 4.1.362005-10-06
CVE-2005-3164 [LOW] CWE-200 CVE-2005-3164: The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request,
nvd
CVE-2011-2481P4MEDIUMCVSS 4.6v7.0.0v7.0.1+13 more2011-08-15
CVE-2011-2481 [MEDIUM] CVE-2011-2481: Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other w Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of
nvd
CVE-2021-43980P4LOWCVSS 3.7≥ 8.5.0, ≤ 8.5.77≥ 9.0.0, ≤ 9.0.60+2 more2022-09-28
CVE-2021-43980 [LOW] CWE-362 CVE-2021-43980: The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported t The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Proc
nvd
CVE-2012-4534P4LOWCVSS 2.6v6.0v6.0.0+55 more2012-12-19
CVE-2012-4534 [LOW] CWE-399 CVE-2012-4534: org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.
nvd
CVE-2007-3384P4MEDIUMCVSS 4.3v3.3v3.3.1+2 more2007-08-08
CVE-2007-3384 [MEDIUM] CVE-2007-3384: Multiple cross-site scripting (XSS) vulnerabilities in examples/servlet/CookieExample in Apache Tomc Multiple cross-site scripting (XSS) vulnerabilities in examples/servlet/CookieExample in Apache Tomcat 3.3 through 3.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Value field, related to error messages.
nvd
CVE-2013-2071P4LOWCVSS 2.6v7.0.0v7.0.1+26 more2013-06-01
CVE-2013-2071 [LOW] CWE-200 CVE-2013-2071: java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not prop java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that re
nvd
CVE-2001-0829P4MEDIUMCVSS 5.1v3.2.12001-12-06
CVE-2001-0829 [MEDIUM] CVE-2001-0829: A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Ja A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.
nvd
CVE-2002-2008P4MEDIUMCVSS 5.0v4.0.32002-12-31
CVE-2002-2008 [MEDIUM] CVE-2002-2008: Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP requ Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the information in an error message.
nvd
CVE-2007-2450P4LOWCVSS 3.5v4.0.0v4.0.1+85 more2007-06-14
CVE-2007-2450 [LOW] CWE-79 CVE-2007-2450: Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web appl Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, an
nvd
CVE-2011-2526P4MEDIUMCVSS 4.4v5.5.0v5.5.1+77 more2011-07-14
CVE-2011-2526 [MEDIUM] CWE-20 CVE-2011-2526: Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enable Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or cause a denial of service (infinite loop or JVM crash) by leveraging an untrusted web applicat
nvd
CVE-2003-0045P4MEDIUMCVSS 5.0v3.0v3.1+7 more2003-02-07
CVE-2003-0045 [MEDIUM] CVE-2003-0045: Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.
nvd
CVE-2008-4308P4LOWCVSS 2.6v4.1.32v4.1.33+12 more2009-02-26
CVE-2008-4308 [LOW] CWE-200 CVE-2008-4308: The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.
nvd
CVE-2010-3718P4LOWCVSS 1.2v7.0.0v7.0.1+61 more2011-02-10
CVE-2010-3718 [LOW] CVE-2010-3718: Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.
nvd
CVE-2011-2204P4LOWCVSS 1.9v5.5.0v5.5.1+76 more2011-06-29
CVE-2011-2204 [LOW] CWE-200 CVE-2011-2204: Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserData Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.
nvd