CVEs (274)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache DebianOracle3Debian Linux Hospitality Cruise Shipboard Property Management SystemTomcatJun 17, 2026 May 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted...Show more |
3Apache DebianOracle7Agile Engineering Data Management Communications Cloud Native Core PolicyDebian Linux+4 moreJun 17, 2026 Jan 27, 2022 N/A· v4 7.0 HIGH· v3 3.7 LOW· v2 The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to...Show more |
4Apache DebianNetapp+1 more18Agile Engineering Data Management Big Data Spatial And GraphCommunications Diameter Signaling Router+15 moreJun 17, 2026 Oct 14, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade conne...Show more |
3Apache DebianNetapp3Debian Linux Management Services For Element Software And Netapp HciTomcatJun 17, 2026 Sep 16, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet...Show more |
4Apache DebianMcafee+1 more23Agile Plm Agile Product Lifecycle ManagementCommunications Cloud Native Core Policy+20 moreAug 25, 2026 Jul 12, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used...Show more |
3Apache DebianOracle7Communications Cloud Native Core Policy Communications Diameter Signaling RouterCommunications Pricing Design Center+4 moreJun 17, 2026 Jul 12, 2021 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache...Show more |
3Apache McafeeOracle3Big Data Spatial And Graph Epolicy OrchestratorTomcatJun 17, 2026 Jul 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated...Show more |
3Apache DebianOracle13Agile Plm Agile Product Lifecycle ManagementCommunications Cloud Native Core Policy+10 moreAug 25, 2026 Mar 1, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tom...Show more |
3Apache DebianOracle13Agile Plm Agile Product Lifecycle ManagementCommunications Cloud Native Core Policy+10 moreAug 25, 2026 Mar 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to...Show more |
3Apache DebianOracle4Agile Plm Agile Product Lifecycle ManagementDebian Linux+1 moreAug 25, 2026 Jan 14, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code discl...Show more |
4Apache DebianNetapp+1 more12Blockchain Platform Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Policy+9 moreJun 17, 2026 Dec 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 c...Show more |
3Apache DebianOracle4Debian Linux Instantis EnterprisetrackSd Wan Edge+1 moreJun 17, 2026 Oct 12, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol...Show more |
7Apache CanonicalDebian+4 more19Agile Engineering Data Management Agile PlmAgile Product Lifecycle Management+16 moreAug 25, 2026 Jul 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite lo...Show more |
6Apache CanonicalDebian+3 more15Agile Engineering Data Management Agile PlmAgile Product Lifecycle Management+12 moreAug 25, 2026 Jul 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were ma...Show more |
A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP...Show more |
6Apache CanonicalDebian+3 more8Debian Linux LeapMysql Enterprise Monitor+5 moreJun 17, 2026 Jun 26, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such reques...Show more |
7Apache CanonicalDebian+4 more27Agile Engineering Data Management Agile PlmAgile Product Lifecycle Management+24 moreAug 25, 2026 May 20, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is...Show more |
7Apache BlackberryDebian+4 more22Agile Engineering Data Management Agile PlmAgile Product Lifecycle Management+19 moreAug 25, 2026 Feb 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If su...Show more |
6Apache CanonicalDebian+3 more20Agile Engineering Data Management Agile Product Lifecycle ManagementCommunications Element Manager+17 moreJun 17, 2026 Feb 24, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a po...Show more |
5Apache DebianNetapp+2 more17Agile Engineering Data Management Agile PlmAgile Product Lifecycle Management+14 moreAug 25, 2026 Feb 24, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed...Show more |