cbcvebase.

Apache Tomcat vulnerabilities

272 known vulnerabilities affecting apache/tomcat.

Total CVEs
272
CISA KEV
7
actively exploited
Public exploits
55
Exploited in wild
9
Severity breakdown
CRITICAL25HIGH90MEDIUM141LOW16

Vulnerabilities

Page 5 of 14
CVE-2025-49125P3HIGHCVSS 7.5≥ 9.0.0, < 9.0.106≥ 10.1.0, < 10.1.42+1 more2025-06-16
CVE-2025-49125 [HIGH] CWE-288 CVE-2025-49125: Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowin
nvd
CVE-2003-0042P4MEDIUMCVSS 5.0PoCv3.0v3.1+7 more2003-02-07
CVE-2003-0042 [MEDIUM] CVE-2003-0042: Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list d Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.
nvd
CVE-2015-5346P3HIGHCVSS 8.1v7.0.0v7.0.2+61 more2016-02-25
CVE-2015-5346 [HIGH] CVE-2015-5346: Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to Coyote
nvd
CVE-2013-6357P4MEDIUMCVSS 6.8PoC≤ 5.5.25v1.1.3+89 more2013-11-13
CVE-2013-6357 [MEDIUM] CWE-352 CVE-2013-6357: Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 a Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a /manager/html/undeploy?path= URI. NOTE: the vendor disputes the significance
nvd
CVE-2016-3092P3HIGHCVSS 7.5v9.0.0v8.0.0+74 more2016-07-04
CVE-2016-3092 [HIGH] CWE-20 CVE-2016-3092: The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x be The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
nvd
CVE-2022-25762P3HIGHCVSS 8.6≥ 8.5.0, < 8.5.76≥ 9.0.0, < 9.0.212022-05-13
CVE-2022-25762 [HIGH] CWE-404 CVE-2022-25762: If a web application sends a WebSocket message concurrently with the WebSocket connection closing wh If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to b
nvd
CVE-2019-17563P3HIGHCVSS 7.5≥ 7.0.0, ≤ 7.0.98≥ 8.5.0, ≤ 8.5.49+1 more2019-12-23
CVE-2019-17563 [HIGH] CWE-384 CVE-2019-17563: When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7 When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.
nvd
CVE-2007-3382P4MEDIUMCVSS 4.3PoCv3.3v3.3.1+82 more2007-08-14
CVE-2007-3382 [MEDIUM] CWE-200 CVE-2007-3382: Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 t Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.
nvd
CVE-2016-8745P3HIGHCVSS 7.5v7.0.0v7.0.1+121 more2017-08-10
CVE-2016-8745 [HIGH] CWE-388 CVE-2016-8745: A bug in the error handling of the send file code for the NIO HTTP connector in Apache Tomcat 9.0.0. A bug in the error handling of the send file code for the NIO HTTP connector in Apache Tomcat 9.0.0.M1 to 9.0.0.M13, 8.5.0 to 8.5.8, 8.0.0.RC1 to 8.0.39, 7.0.0 to 7.0.73 and 6.0.16 to 6.0.48 resulted in the current Processor object being added to the Processor cache multiple times. This in turn meant that the same Processor could be used for concurrent
nvd
CVE-2002-1567P4MEDIUMCVSS 6.8PoCv4.1.02003-10-06
CVE-2002-1567 [MEDIUM] CVE-2002-1567: Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arb Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.
nvd
CVE-2017-5648P3CRITICALCVSS 9.1v7.0.0v7.0.1+129 more2017-04-17
CVE-2017-5648 [CRITICAL] CWE-668 CVE-2017-5648: While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tom While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to
nvd
CVE-2019-2684P3MEDIUMCVSS 5.9≥ 7.0.0, ≤ 7.0.97≥ 8.5.0, ≤ 8.5.47+2 more2019-04-23
CVE-2019-2684 [MEDIUM] CVE-2019-2684: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supp Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2002-2272P4HIGHCVSS 7.8PoCv4.0.0v4.0.1+12 more2002-12-31
CVE-2002-2272 [HIGH] CWE-119 CVE-2002-2272: Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote att Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
nvd
CVE-2018-1336P3HIGHCVSS 7.5≥ 7.0.28, ≤ 7.0.86≥ 8.0.0, ≤ 8.0.51+4 more2018-08-02
CVE-2018-1336 [HIGH] CWE-835 CVE-2018-1336: An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an in An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
nvd
CVE-2026-66422P3HIGHCVSS 8.1≥ 7.0.97, ≤ 7.0.109≥ 8.5.46, < 9.0.121+2 more2026-08-25
CVE-2026-66422 [HIGH] CWE-285 CVE-2026-66422: Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being i Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120. The follo
nvd
CVE-2017-5651P3CRITICALCVSS 9.8v8.5.0v8.5.1+12 more2017-04-17
CVE-2017-5651 [CRITICAL] CVE-2017-5651: In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors i In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processing. If the send file processing completed quickly, it was possible for the Processor to be added to the processor cache twice. This could result in the same Processor being used for multiple requests which in tu
nvd
CVE-2026-24880P3HIGHCVSS 7.5≥ 9.0.0, < 9.0.116≥ 10.1.0, < 10.1.53+1 more2026-04-09
CVE-2026-24880 [HIGH] CWE-444 CVE-2026-24880: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Ap Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other, unsupported version
nvd
CVE-2013-4444P3MEDIUMCVSS 6.8≤ 7.0.39v7.0.0+33 more2014-09-12
CVE-2013-4444 [MEDIUM] CWE-94 CVE-2013-4444: Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations inv Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.
nvd
CVE-2017-5664P3HIGHCVSS 7.5v7.0.0v7.0.1+133 more2017-06-06
CVE-2017-5664 [HIGH] CWE-755 CVE-2017-5664: The error page mechanism of the Java Servlet Specification requires that, when an error occurs and a The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is configured for the error that occurred, the original request and response are forwarded to the error page. This means that the request is presented to the error page with the original HTTP method. If the error page is a static file, expect
nvd
CVE-2017-7675P3HIGHCVSS 7.5v8.5.0v8.5.1+15 more2017-08-11
CVE-2017-7675 [HIGH] CWE-22 CVE-2017-7675: The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a numb The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. It was therefore possible to bypass security constraints using a specially crafted URL.
nvd
Apache Tomcat vulnerabilities | cvebase