Apache

Tomcat

231 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.58%
  • Veröffentlicht 13.03.2024 16:15:29
  • Zuletzt bearbeitet 07.08.2025 12:15:27

Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0....

  • EPSS 52.45%
  • Veröffentlicht 13.03.2024 16:15:29
  • Zuletzt bearbeitet 19.05.2025 13:02:08

Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset unt...

  • EPSS 67.59%
  • Veröffentlicht 19.01.2024 11:15:08
  • Zuletzt bearbeitet 13.06.2025 16:15:24

Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Users are recommended to upgrade to version 8.5.64 onwards or 9.0...

  • EPSS 56.3%
  • Veröffentlicht 28.11.2023 16:15:06
  • Zuletzt bearbeitet 07.08.2025 11:15:28

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer head...

  • EPSS 0.73%
  • Veröffentlicht 10.10.2023 19:15:09
  • Zuletzt bearbeitet 07.08.2025 11:15:27

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially c...

  • EPSS 0.24%
  • Veröffentlicht 10.10.2023 18:15:18
  • Zuletzt bearbeitet 13.02.2025 17:17:09

Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial o...

  • EPSS 0.69%
  • Veröffentlicht 10.10.2023 18:15:18
  • Zuletzt bearbeitet 07.08.2025 11:15:27

Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could ...

Warnung Medienbericht Exploit
  • EPSS 94.44%
  • Veröffentlicht 10.10.2023 14:15:10
  • Zuletzt bearbeitet 11.06.2025 17:29:54

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • EPSS 11.34%
  • Veröffentlicht 25.08.2023 21:15:09
  • Zuletzt bearbeitet 07.08.2025 11:15:27

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from ...

  • EPSS 0.23%
  • Veröffentlicht 21.06.2023 11:15:09
  • Zuletzt bearbeitet 21.11.2024 08:07:46

A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJ...