cbcvebase.

Apache Tomcat vulnerabilities

272 known vulnerabilities affecting apache/tomcat.

Total CVEs
272
CISA KEV
7
actively exploited
Public exploits
55
Exploited in wild
9
Severity breakdown
CRITICAL25HIGH90MEDIUM141LOW16

Vulnerabilities

Page 14 of 14
CVE-2021-43980P4LOWCVSS 3.7≥ 8.5.0, ≤ 8.5.77≥ 9.0.0, ≤ 9.0.60+2 more2022-09-28
CVE-2021-43980 [LOW] CWE-362 CVE-2021-43980: The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported t The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Proc
nvd
CVE-2012-4534P4LOWCVSS 2.6v6.0v6.0.0+55 more2012-12-19
CVE-2012-4534 [LOW] CWE-399 CVE-2012-4534: org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.
nvd
CVE-2007-3384P4MEDIUMCVSS 4.3v3.3v3.3.1+2 more2007-08-08
CVE-2007-3384 [MEDIUM] CVE-2007-3384: Multiple cross-site scripting (XSS) vulnerabilities in examples/servlet/CookieExample in Apache Tomc Multiple cross-site scripting (XSS) vulnerabilities in examples/servlet/CookieExample in Apache Tomcat 3.3 through 3.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Value field, related to error messages.
nvd
CVE-2001-0829P4MEDIUMCVSS 5.1v3.2.12001-12-06
CVE-2001-0829 [MEDIUM] CVE-2001-0829: A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Ja A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.
nvd
CVE-2002-2008P4MEDIUMCVSS 5.0v4.0.32002-12-31
CVE-2002-2008 [MEDIUM] CVE-2002-2008: Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP requ Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the information in an error message.
nvd
CVE-2007-2450P4LOWCVSS 3.5v4.0.0v4.0.1+85 more2007-06-14
CVE-2007-2450 [LOW] CWE-79 CVE-2007-2450: Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web appl Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, an
nvd
CVE-2011-2526P4MEDIUMCVSS 4.4v5.5.0v5.5.1+77 more2011-07-14
CVE-2011-2526 [MEDIUM] CWE-20 CVE-2011-2526: Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enable Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or cause a denial of service (infinite loop or JVM crash) by leveraging an untrusted web applicat
nvd
CVE-2003-0045P4MEDIUMCVSS 5.0v3.0v3.1+7 more2003-02-07
CVE-2003-0045 [MEDIUM] CVE-2003-0045: Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.
nvd
CVE-2008-4308P4LOWCVSS 2.6v4.1.32v4.1.33+12 more2009-02-26
CVE-2008-4308 [LOW] CWE-200 CVE-2008-4308: The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.
nvd
CVE-2010-3718P4LOWCVSS 1.2v7.0.0v7.0.1+61 more2011-02-10
CVE-2010-3718 [LOW] CVE-2010-3718: Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.
nvd
CVE-2011-2204P4LOWCVSS 1.9v5.5.0v5.5.1+76 more2011-06-29
CVE-2011-2204 [LOW] CWE-200 CVE-2011-2204: Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserData Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.
nvd
CVE-2013-0346P4LOWCVSS 2.1v7.0.0v7.0.1+49 more2014-02-15
CVE-2013-0346 [LOW] CWE-264 CVE-2013-0346: Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might a Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."
nvd
Apache Tomcat vulnerabilities | cvebase