Apache

Tomcat

235 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 18.61%
  • Veröffentlicht 03.10.2016 15:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and libtomcat6-java packages before 6.0.35-1ubuntu3.8 on Ubuntu 12.04 LTS, the tomcat7 and libtomcat7-jav...

  • EPSS 70.69%
  • Veröffentlicht 19.07.2016 02:00:20
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, wh...

  • EPSS 36.48%
  • Veröffentlicht 04.07.2016 22:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (...

  • EPSS 0.26%
  • Veröffentlicht 25.02.2016 01:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, wh...

  • EPSS 10.32%
  • Veröffentlicht 25.02.2016 01:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass intended SecurityManager restric...

  • EPSS 0.62%
  • Veröffentlicht 25.02.2016 01:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows remote aut...

  • EPSS 6.09%
  • Veröffentlicht 25.02.2016 01:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protec...

  • EPSS 27.27%
  • Veröffentlicht 25.02.2016 01:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to ...

  • EPSS 30.82%
  • Veröffentlicht 25.02.2016 01:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence o...

  • EPSS 1.09%
  • Veröffentlicht 25.02.2016 01:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.....