CVE-2024-52316
- EPSS 1.76%
- Veröffentlicht 18.11.2024 12:15:18
- Zuletzt bearbeitet 07.11.2025 16:15:59
Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly s...
CVE-2024-52317
- EPSS 6.95%
- Veröffentlicht 18.11.2024 12:15:18
- Zuletzt bearbeitet 15.05.2025 17:51:16
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0...
CVE-2024-38286
- EPSS 0.55%
- Veröffentlicht 07.11.2024 08:15:13
- Zuletzt bearbeitet 03.11.2025 21:16:14
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL a...
CVE-2024-34750
- EPSS 17.25%
- Veröffentlicht 03.07.2024 20:15:04
- Zuletzt bearbeitet 03.11.2025 20:16:12
Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active...
CVE-2024-23672
- EPSS 0.58%
- Veröffentlicht 13.03.2024 16:15:29
- Zuletzt bearbeitet 07.08.2025 12:15:27
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0....
CVE-2024-24549
- EPSS 52.45%
- Veröffentlicht 13.03.2024 16:15:29
- Zuletzt bearbeitet 29.10.2025 12:15:34
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset unt...
CVE-2024-21733
- EPSS 70.68%
- Veröffentlicht 19.01.2024 11:15:08
- Zuletzt bearbeitet 03.11.2025 21:16:06
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL versions may also be affected. Users are recommended t...
CVE-2023-46589
- EPSS 54.62%
- Veröffentlicht 28.11.2023 16:15:06
- Zuletzt bearbeitet 07.08.2025 11:15:28
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer head...
CVE-2023-45648
- EPSS 0.73%
- Veröffentlicht 10.10.2023 19:15:09
- Zuletzt bearbeitet 07.08.2025 11:15:27
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially c...
CVE-2023-42794
- EPSS 0.32%
- Veröffentlicht 10.10.2023 18:15:18
- Zuletzt bearbeitet 29.10.2025 12:15:33
Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial o...