cbcvebase.

Debian Tomcat9 vulnerabilities

67 known vulnerabilities affecting debian/tomcat9.

Total CVEs
67
CISA KEV
3
actively exploited
Public exploits
10
Exploited in wild
4
Severity breakdown
CRITICAL8HIGH37MEDIUM15LOW7

Vulnerabilities

Page 2 of 4
CVE-2023-28709P3HIGHCVSS 7.5fixed in tomcat10 10.1.6-1+deb12u1 (bookworm)2023
CVE-2023-28709 [HIGH] CVE-2023-28709: tomcat10 - The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-... The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string
debian
CVE-2025-66614P2CRITICALCVSS 9.1fixed in tomcat10 10.1.52-1~deb12u1 (bookworm)2025
CVE-2025-66614 [CRITICAL] CVE-2025-66614: tomcat10 - Improper Input Validation vulnerability. This issue affects Apache Tomcat: from... Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate that the host n
debian
CVE-2020-13934P3HIGHCVSS 7.5fixed in tomcat9 9.0.37-1 (bookworm)2020
CVE-2020-13934 [HIGH] CVE-2020-13934: tomcat9 - An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.... An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service. Scope: local bookworm: resolved (fixed in 9.0.37-1) bullseye: resolved (fixe
debian
CVE-2023-45648P3MEDIUMCVSS 5.3PoCfixed in tomcat10 10.1.6-1+deb12u1 (bookworm)2023
CVE-2023-45648 [MEDIUM] CVE-2023-45648: tomcat10 - Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 t... Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the poss
debian
CVE-2021-33037P3MEDIUMCVSS 5.3fixed in tomcat9 9.0.43-2 (bookworm)2021
CVE-2021-33037 [MEDIUM] CVE-2021-33037: tomcat9 - Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did no... Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/
debian
CVE-2024-24549P3HIGHCVSS 7.5fixed in tomcat10 10.1.6-1+deb12u2 (bookworm)2024
CVE-2024-24549 [HIGH] CVE-2024-24549: tomcat10 - Denial of Service due to improper input validation vulnerability for HTTP/2 requ... Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, f
debian
CVE-2021-25122P3HIGHCVSS 7.5fixed in tomcat9 9.0.43-1 (bookworm)2021
CVE-2021-25122 [HIGH] CVE-2021-25122: tomcat9 - When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1... When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request. Scope: local bookworm: resolved (fixed in 9.0.43-1) bullseye: reso
debian
CVE-2020-17527P3HIGHCVSS 7.5fixed in tomcat9 9.0.40-1 (bookworm)2020
CVE-2020-17527 [HIGH] CVE-2020-17527: tomcat9 - While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to ... While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connect
debian
CVE-2025-49125P3HIGHCVSS 7.5fixed in tomcat10 10.1.52-1~deb12u1 (bookworm)2025
CVE-2025-49125 [HIGH] CVE-2025-49125: tomcat10 - Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache... Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowing those secur
debian
CVE-2020-11996P3HIGHCVSS 7.5fixed in tomcat9 9.0.36-1 (bookworm)2020
CVE-2020-11996 [HIGH] CVE-2020-11996: tomcat9 - A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 ... A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive. Scope: local bookworm: resolved (fixed in 9.0.36-1) bullseye: r
debian
CVE-2016-3092P3HIGHCVSS 7.5fixed in libcommons-fileupload-java 1.3.2-1 (bookworm)2016
CVE-2016-3092 [HIGH] CVE-2016-3092: libcommons-fileupload-java - The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in ... The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string. Scope: local bookworm: resolved (fixed in 1.3.2-1) bulls
debian
CVE-2022-25762P3HIGHCVSS 8.6fixed in tomcat9 9.0.22-1 (bookworm)2022
CVE-2022-25762 [HIGH] CVE-2022-25762: tomcat9 - If a web application sends a WebSocket message concurrently with the WebSocket c... If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the
debian
CVE-2019-17563P3HIGHCVSS 7.5fixed in tomcat9 9.0.31-1 (bookworm)2019
CVE-2019-17563 [HIGH] CVE-2019-17563: tomcat9 - When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8... When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability. Scope: local boo
debian
CVE-2025-48989P3HIGHCVSS 7.5fixed in tomcat10 10.1.52-1~deb12u1 (bookworm)2025
CVE-2025-48989 [HIGH] CVE-2025-48989: tomcat10 - Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat... Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected. Users are recommended to upgrade to one of versions 11.0.10, 10.1.44 or
debian
CVE-2025-46701P3HIGHCVSS 7.3fixed in tomcat10 10.1.52-1~deb12u1 (bookworm)2025
CVE-2025-46701 [HIGH] CVE-2025-46701: tomcat10 - Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servl... Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104. The following versions we
debian
CVE-2021-24122P3LOWCVSS 5.9fixed in tomcat9 9.0.40-1 (bookworm)2021
CVE-2021-24122 [MEDIUM] CVE-2021-24122: tomcat9 - When serving resources from a network location using the NTFS file system, Apach... When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root cause was the unexpected behaviour of the JRE API File.getCanonicalPath() which in turn was caused by the i
debian
CVE-2024-34750P3HIGHCVSS 7.5fixed in tomcat10 10.1.34-0+deb12u1 (bookworm)2024
CVE-2024-34750 [HIGH] CVE-2024-34750: tomcat10 - Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption v... Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain ope
debian
CVE-2023-46589P3HIGHCVSS 7.5fixed in tomcat10 10.1.6-1+deb12u2 (bookworm)2023
CVE-2023-46589 [HIGH] CVE-2023-46589: tomcat10 - Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 t... Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to t
debian
CVE-2025-53506P3HIGHCVSS 7.5fixed in tomcat10 10.1.52-1~deb12u1 (bookworm)2025
CVE-2025-53506 [HIGH] CVE-2025-53506: tomcat10 - Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 cl... Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE
debian
CVE-2025-52520P3HIGHCVSS 7.5fixed in tomcat10 10.1.52-1~deb12u1 (bookworm)2025
CVE-2025-52520 [HIGH] CVE-2025-52520: tomcat10 - For some unlikely configurations of multipart upload, an Integer Overflow vulner... For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be
debian
Debian Tomcat9 vulnerabilities | cvebase