cbcvebase.

Apache Tomcat vulnerabilities

261 known vulnerabilities affecting apache/tomcat.

Total CVEs
261
CISA KEV
6
actively exploited
Public exploits
55
Exploited in wild
8
Severity breakdown
CRITICAL21HIGH85MEDIUM139LOW16

Vulnerabilities

Page 8 of 14
CVE-2013-2185P3HIGHCVSS 7.5≤ 7.0.392014-01-19
CVE-2013-2185 [HIGH] CWE-20 CVE-2013-2185: The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat J The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186. NOTE: this issue is reportedly dispute
nvd
CVE-2016-0763P3MEDIUMCVSS 6.3v7.0.0v7.0.2+63 more2016-02-25
CVE-2016-0763 [MEDIUM] CWE-264 CVE-2016-0763: The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7 The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write
nvd
CVE-2021-25329P3HIGHCVSS 7.0≥ 7.0.0, ≤ 7.0.107≥ 8.5.0, ≤ 8.5.61+3 more2021-03-01
CVE-2021-25329 [HIGH] CVE-2021-25329: The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously
nvd
CVE-2020-8022P3HIGHCVSS 7.8fixed in 8.0.53-29.32.1fixed in 9.0.35-3.39.1+1 more2020-06-29
CVE-2020-8022 [HIGH] CWE-276 CVE-2020-8022: A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux Enterprise Server 12-SP3-LTSS, SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 12-SP5, SUSE Linux En
nvd
CVE-2008-5515P3MEDIUMCVSS 5.0v4.1.0v4.1.1+78 more2009-06-16
CVE-2008-5515 [MEDIUM] CWE-22 CVE-2008-5515: Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences an
nvd
CVE-2024-52317P3MEDIUMCVSS 6.5≥ 9.0.92, < 9.0.96≥ 10.1.27, < 10.1.31+1 more2024-11-18
CVE-2024-52317 [MEDIUM] CWE-326 CVE-2024-52317: Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the re Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95. Users are recommen
nvd
CVE-2024-23672P3MEDIUMCVSS 6.3≥ 8.5.0, < 8.5.99≥ 9.0.0, < 9.0.86+2 more2024-03-13
CVE-2024-23672 [MEDIUM] CWE-459 CVE-2024-23672: Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSock Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Olde
nvd
CVE-2026-55955P3MEDIUMCVSS 6.5fixed in 9.0.119≥ 10.1.0, < 10.1.56+1 more2026-06-29
CVE-2026-55955 [MEDIUM] CWE-287 CVE-2026-55955: Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the Encryptio Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to
nvd
CVE-2016-9775P3HIGHCVSS 7.8v6.0v7.0+1 more2017-03-23
CVE-2016-9775 [HIGH] CWE-264 CVE-2016-9775: The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45 The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45+dfsg-1~deb8u1 on Debian jessie, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u7 on Debian wheezy, before 7.0.56-3+deb8u6 on Debian jessie, before 7.0.52-1ubuntu0.8 on Ubuntu 14.04 LTS, and
nvd
CVE-2016-6817P3HIGHCVSS 7.5v8.5.0v8.5.1+6 more2017-08-10
CVE-2016-6817 [HIGH] CWE-119 CVE-2016-6817: The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infini The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possible.
nvd
CVE-2013-4286P3MEDIUMCVSS 5.8v7.0.0v7.0.1+171 more2014-02-26
CVE-2013-4286 [MEDIUM] CVE-2013-4286: Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle certain inconsistent HTTP request headers, which allows remote attackers to trigger incorrect identification of a request's length and conduct request-smuggling attacks via (1) multiple Content-Length headers or (2
nvd
CVE-2023-34981P3HIGHCVSS 7.5v8.5.88v9.0.74+2 more2023-06-21
CVE-2023-34981 [HIGH] CWE-732 CVE-2023-34981: A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant th A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an informat
nvd
CVE-2018-8037P3MEDIUMCVSS 5.9≥ 8.5.5, ≤ 8.5.31≥ 9.0.1, ≤ 9.0.9+20 more2018-08-02
CVE-2018-8037 [MEDIUM] CWE-362 CVE-2018-8037: If an async request was completed by the application at the same time as the container triggered the If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async
nvd
CVE-2014-7810P3MEDIUMCVSS 5.0v6.0.0v6.0.1+101 more2015-06-07
CVE-2014-7810 [MEDIUM] CWE-284 CVE-2014-7810: The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, a The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrec
nvd
CVE-2016-9774P3HIGHCVSS 7.8v6.0v7.0+1 more2017-03-23
CVE-2016-9774 [HIGH] CWE-59 CVE-2016-9774: The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0. The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u8 on Debian wheezy, before 7.0.56-3+deb8u6 on Debian jessie, before 7.0.52-1ubuntu0.8 on Ubuntu 14.04 LTS, and on Ubuntu 12.04 LTS, 16.04 LTS, and 16.10; an
nvd
CVE-2012-5887P3MEDIUMCVSS 5.0≥ 5.5.0, < 5.5.36≥ 6.0.0, < 6.0.36+1 more2012-11-17
CVE-2012-5887 [MEDIUM] CWE-287 CVE-2012-5887: The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x befor The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid req
nvd
CVE-2009-2693P3MEDIUMCVSS 5.8v5.5.0v5.5.1+49 more2010-01-28
CVE-2009-2693 [MEDIUM] CWE-22 CVE-2009-2693: Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 all Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrated by a ../../bin/catalina.bat entry.
nvd
CVE-2016-0762P3MEDIUMCVSS 5.9≥ 6.0.0, ≤ 6.0.45≥ 7.0.0, ≤ 7.0.70+3 more2017-08-10
CVE-2016-0762 [MEDIUM] CWE-203 CVE-2016-0762: The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a timing attack possible to determine valid user names. Note that the default configuration includes the LockOutRealm
nvd
CVE-2025-55668P3MEDIUMCVSS 6.5≥ 9.0.1, < 9.0.106≥ 10.0.0, < 10.1.42+2 more2025-08-13
CVE-2025-55668 [MEDIUM] CWE-384 CVE-2025-55668: Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
nvd
CVE-2012-3546P3MEDIUMCVSS 4.3v6.0v6.0.0+56 more2012-12-19
CVE-2012-3546 [MEDIUM] CWE-264 CVE-2012-3546: org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, w org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.
nvd
Apache Tomcat vulnerabilities | cvebase