Apache Tomcat vulnerabilities

235 known vulnerabilities affecting apache/tomcat.

Total CVEs
235
CISA KEV
6
actively exploited
Public exploits
50
Exploited in wild
5
Severity breakdown
CRITICAL13HIGH74MEDIUM133LOW15

Vulnerabilities

Page 7 of 12
CVE-2013-4590MEDIUMCVSS 4.3v8.0.0≤ 6.0.37+172 more2014-02-26
CVE-2013-4590 [MEDIUM] CWE-200 CVE-2013-4590: Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to a
nvd
CVE-2014-0033MEDIUMCVSS 4.3v6.0.33v6.0.34+3 more2014-02-26
CVE-2014-0033 [MEDIUM] CWE-20 CVE-2014-0033: org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not con org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not consider the disableURLRewriting setting when handling a session ID in a URL, which allows remote attackers to conduct session fixation attacks via a crafted URL.
nvd
CVE-2013-4286MEDIUMCVSS 5.8v7.0.0v7.0.1+171 more2014-02-26
CVE-2013-4286 [MEDIUM] CVE-2013-4286: Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle certain inconsistent HTTP request headers, which allows remote attackers to trigger incorrect identification of a request's length and conduct request-smuggling attacks via (1) multiple Content-Length headers or (2
nvd
CVE-2013-4322MEDIUMCVSS 4.3v7.0.0v7.0.1+172 more2014-02-26
CVE-2013-4322 [MEDIUM] CVE-2013-4322: Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a trailer field, which allows remote attackers to cause a denial of service by streaming data. NOTE: this vulnerability exists
nvd
CVE-2013-0346LOWCVSS 2.1v7.0.0v7.0.1+49 more2014-02-15
CVE-2013-0346 [LOW] CWE-264 CVE-2013-0346: Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might a Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."
nvd
CVE-2013-2185HIGHCVSS 7.5≤ 7.0.392014-01-19
CVE-2013-2185 [HIGH] CWE-20 CVE-2013-2185: The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat J The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186. NOTE: this issue is reportedly dispute
nvd
CVE-2013-6357MEDIUMCVSS 6.8PoC≤ 5.5.25v1.1.3+89 more2013-11-13
CVE-2013-6357 [MEDIUM] CWE-352 CVE-2013-6357: Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 a Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a /manager/html/undeploy?path= URI. NOTE: the vendor disputes the significance
nvd
CVE-2013-2067MEDIUMCVSS 6.8v6.0.21v6.0.24+38 more2013-06-01
CVE-2013-2067 [MEDIUM] CWE-287 CVE-2013-2067: java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during complet
nvd
CVE-2012-3544MEDIUMCVSS 5.0v6.0v6.0.0+57 more2013-06-01
CVE-2012-3544 [MEDIUM] CWE-20 CVE-2012-3544: Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in c Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.
nvd
CVE-2013-2071LOWCVSS 2.6v7.0.0v7.0.1+26 more2013-06-01
CVE-2013-2071 [LOW] CWE-200 CVE-2013-2071: java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not prop java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that re
nvd
CVE-2012-3546MEDIUMCVSS 4.3v6.0v6.0.0+56 more2012-12-19
CVE-2012-3546 [MEDIUM] CWE-264 CVE-2012-3546: org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, w org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.
nvd
CVE-2012-4431MEDIUMCVSS 4.3v6.0v6.0.0+57 more2012-12-19
CVE-2012-4431 [MEDIUM] CWE-264 CVE-2012-4431: org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x bef org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.
nvd
CVE-2012-4534LOWCVSS 2.6v6.0v6.0.0+55 more2012-12-19
CVE-2012-4534 [LOW] CWE-399 CVE-2012-4534: org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.
nvd
CVE-2012-5568MEDIUMCVSS 5.0≥ 7.0.0, ≤ 7.0.1052012-11-30
CVE-2012-5568 [MEDIUM] CVE-2012-5568: Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
nvd
CVE-2012-5886MEDIUMCVSS 5.0v5.5.0v5.5.1+92 more2012-11-17
CVE-2012-5886 [MEDIUM] CWE-287 CVE-2012-5886: The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x befor The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.
nvd
CVE-2012-5885MEDIUMCVSS 5.0v5.5.0v5.5.1+92 more2012-11-17
CVE-2012-5885 [MEDIUM] CVE-2012-5885: The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in A The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrict
nvd
CVE-2012-5887MEDIUMCVSS 5.0≥ 5.5.0, < 5.5.36≥ 6.0.0, < 6.0.36+1 more2012-11-17
CVE-2012-5887 [MEDIUM] CWE-287 CVE-2012-5887: The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x befor The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid req
nvd
CVE-2012-2733MEDIUMCVSS 5.0v6.0v6.0.0+55 more2012-11-16
CVE-2012-2733 [MEDIUM] CWE-20 CVE-2012-2733: java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a large amount of header data.
nvd
CVE-2012-0022MEDIUMCVSS 5.0v5.5.0v5.5.1+87 more2012-01-19
CVE-2012-0022 [MEDIUM] CVE-2012-0022: Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient appr Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.
nvd
CVE-2011-3375MEDIUMCVSS 5.0v6.0.30v6.0.31+24 more2012-01-19
CVE-2011-3375 [MEDIUM] CWE-200 CVE-2011-3375: Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
nvd