Apache

Tomcat

288 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.24%
  • Veröffentlicht 23.09.2026 11:14:07
  • Zuletzt bearbeitet 23.09.2026 19:19:14

Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfigProvider as the default provider and multiple web application used that provider, the realm for the first web application to authe...

Medienbericht
  • EPSS 0.12%
  • Veröffentlicht 23.09.2026 11:08:53
  • Zuletzt bearbeitet 30.09.2026 15:22:34

Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10....

  • EPSS 0.41%
  • Veröffentlicht 25.08.2026 22:17:06
  • Zuletzt bearbeitet 27.08.2026 12:40:56

Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session w...

  • EPSS 0.55%
  • Veröffentlicht 25.08.2026 22:17:05
  • Zuletzt bearbeitet 27.08.2026 13:02:31

Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9....

  • EPSS 0.45%
  • Veröffentlicht 25.08.2026 21:59:17
  • Zuletzt bearbeitet 21.09.2026 12:17:17

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11....

  • EPSS 0.55%
  • Veröffentlicht 25.08.2026 21:57:18
  • Zuletzt bearbeitet 27.08.2026 15:15:02

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 thr...

  • EPSS 0.42%
  • Veröffentlicht 25.08.2026 21:55:16
  • Zuletzt bearbeitet 27.08.2026 15:16:11

Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: ...

  • EPSS 0.51%
  • Veröffentlicht 25.08.2026 21:53:05
  • Zuletzt bearbeitet 27.08.2026 15:17:08

Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, ...

  • EPSS 0.68%
  • Veröffentlicht 25.08.2026 21:51:33
  • Zuletzt bearbeitet 27.08.2026 15:17:49

Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window...

  • EPSS 0.53%
  • Veröffentlicht 25.08.2026 21:49:13
  • Zuletzt bearbeitet 27.08.2026 15:19:42

Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended...