Apache

Tomcat

238 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.11%
  • Veröffentlicht 17.02.2026 18:53:12
  • Zuletzt bearbeitet 11.03.2026 16:16:29

Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response whic...

  • EPSS 0.19%
  • Veröffentlicht 17.02.2026 18:50:43
  • Zuletzt bearbeitet 11.03.2026 16:16:29

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constrai...

  • EPSS 0.04%
  • Veröffentlicht 17.02.2026 18:48:30
  • Zuletzt bearbeitet 11.03.2026 16:16:20

Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known...

Exploit
  • EPSS 1.31%
  • Veröffentlicht 07.11.2025 00:00:00
  • Zuletzt bearbeitet 08.12.2025 16:10:04

In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management module, it is possible to execute any Java class with a parameterless constructor and its methods with parameter t...

  • EPSS 0.17%
  • Veröffentlicht 27.10.2025 17:30:28
  • Zuletzt bearbeitet 14.11.2025 16:53:33

Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediate...

Medienbericht Exploit
  • EPSS 0.41%
  • Veröffentlicht 27.10.2025 17:29:56
  • Zuletzt bearbeitet 14.11.2025 17:44:41

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite quer...

Medienbericht
  • EPSS 0.11%
  • Veröffentlicht 27.10.2025 17:29:50
  • Zuletzt bearbeitet 14.11.2025 17:37:41

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported AN...

  • EPSS 0.02%
  • Veröffentlicht 13.08.2025 13:21:35
  • Zuletzt bearbeitet 04.11.2025 22:16:30

Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are r...

  • EPSS 0.24%
  • Veröffentlicht 13.08.2025 12:11:26
  • Zuletzt bearbeitet 04.11.2025 22:16:17

Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.1...

  • EPSS 0.24%
  • Veröffentlicht 10.07.2025 19:14:23
  • Zuletzt bearbeitet 04.11.2025 22:16:21

Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0....