cbcvebase.

Apache Tomcat vulnerabilities

261 known vulnerabilities affecting apache/tomcat.

Total CVEs
261
CISA KEV
6
actively exploited
Public exploits
55
Exploited in wild
8
Severity breakdown
CRITICAL21HIGH85MEDIUM139LOW16

Vulnerabilities

Page 9 of 14
CVE-2006-7197P3HIGHCVSS 7.8v5.5.152007-04-25
CVE-2006-7197 [HIGH] CVE-2006-7197: The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buf The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.
nvd
CVE-2023-41080P3MEDIUMCVSS 6.1≥ 8.5.0, ≤ 8.5.92≥ 9.0.0, ≤ 9.0.79+2 more2023-08-25
CVE-2023-41080 [MEDIUM] CWE-601 CVE-2023-41080: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apa URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected. The vulnerability is limited to the
nvd
CVE-2011-1088P3MEDIUMCVSS 5.8v7.0.0v7.0.1+8 more2011-03-14
CVE-2011-1088 [MEDIUM] CVE-2011-1088: Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote att Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.
nvd
CVE-2014-0075P3MEDIUMCVSS 5.0v7.0.0v7.0.1+89 more2014-05-31
CVE-2014-0075 [MEDIUM] CWE-189 CVE-2014-0075: Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedIn Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 allows remote attackers to cause a denial of service (resource consumption) via a malformed chunk size in chunked transfer coding of a request during the streaming of
nvd
CVE-2014-0096P3MEDIUMCVSS 4.3v7.0.0v7.0.1+89 more2014-05-31
CVE-2014-0096 [MEDIUM] CWE-264 CVE-2014-0096: java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 does not properly restrict XSLT stylesheets, which allows remote attackers to bypass security-manager restrictions and read arbitrary files via a crafted web application that provides an XML external enti
nvd
CVE-2024-21733P3MEDIUMCVSS 5.3≥ 8.5.7, < 8.5.64≥ 9.0.1, < 9.0.44+1 more2024-01-19
CVE-2024-21733 [MEDIUM] CWE-209 CVE-2024-21733: Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This iss Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL versions may also be affected. Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.
nvd
CVE-2012-5885P3MEDIUMCVSS 5.0v5.5.0v5.5.1+92 more2012-11-17
CVE-2012-5885 [MEDIUM] CVE-2012-5885: The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in A The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrict
nvd
CVE-2011-1184P3MEDIUMCVSS 5.0v5.5.0v5.5.1+74 more2012-01-14
CVE-2011-1184 [MEDIUM] CWE-264 CVE-2011-1184: The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x befor The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, related to lack of checking
nvd
CVE-2016-6794P3MEDIUMCVSS 5.3≥ 6.0.0, ≤ 6.0.45≥ 7.0.0, ≤ 7.0.70+3 more2017-08-10
CVE-2016-6794 [MEDIUM] CVE-2016-6794: When a SecurityManager is configured, a web application's ability to read system properties should b When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to byp
nvd
CVE-2019-12418P3HIGHCVSS 7.0≥ 7.0.0, ≤ 7.0.97≥ 8.5.0, ≤ 8.5.47+1 more2019-12-23
CVE-2019-12418 [HIGH] CVE-2019-12418: When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacke
nvd
CVE-2012-5886P4MEDIUMCVSS 5.0v5.5.0v5.5.1+92 more2012-11-17
CVE-2012-5886 [MEDIUM] CWE-287 CVE-2012-5886: The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x befor The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.
nvd
CVE-2011-1419P3MEDIUMCVSS 5.8v7.0.0v7.0.1+9 more2011-03-14
CVE-2011-1419 [MEDIUM] CVE-2011-1419: Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSe Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
nvd
CVE-2011-1183P4MEDIUMCVSS 5.8v7.0.112011-04-08
CVE-2011-1183 [MEDIUM] CVE-2011-1183: Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
nvd
CVE-2008-0128P4MEDIUMCVSS 5.0≤ 5.5.202008-01-23
CVE-2008-0128 [MEDIUM] CWE-16 CVE-2008-0128: The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5. The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
nvd
CVE-2011-2729P4MEDIUMCVSS 5.0v5.5.32v5.5.33+21 more2011-08-15
CVE-2011-2729 [MEDIUM] CWE-264 CVE-2011-2729: native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.
nvd
CVE-2014-0119P4MEDIUMCVSS 4.3v8.0.0v8.0.1+91 more2014-05-31
CVE-2014-0119 [MEDIUM] CWE-264 CVE-2014-0119: Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, re
nvd
CVE-2011-5062P4MEDIUMCVSS 5.0v5.5.0v5.5.1+74 more2012-01-14
CVE-2011-5062 [MEDIUM] CVE-2011-5062: The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x befor The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.
nvd
CVE-2017-15706P4MEDIUMCVSS 5.3≥ 7.0.79, ≤ 7.0.82≥ 8.0.45, ≤ 8.0.47+3 more2018-01-31
CVE-2017-15706 [MEDIUM] CWE-358 CVE-2017-15706: As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify which script to execute. The update was not correct. As a result, some scripts may have failed to execute as expec
nvd
CVE-2007-5342P4MEDIUMCVSS 6.4v5.5.9v5.5.10+31 more2007-12-27
CVE-2007-5342 [MEDIUM] CWE-264 CVE-2007-5342: The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attrib
nvd
CVE-2022-23181P4HIGHCVSS 7.0≥ 8.5.55, ≤ 8.5.73≥ 9.0.35, ≤ 9.0.56+3 more2022-01-27
CVE-2022-23181 [HIGH] CVE-2022-23181: The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomc The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to
nvd