CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Apache CanonicalDebian+2 more11Agile Engineering Data Management Debian LinuxHyperion Infrastructure Technology+8 moreNov 21, 2024 Dec 23, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too...Show more |
5Apache CanonicalDebian+2 more10Debian Linux Fusion MiddlewareHospitality Guest Access+7 moreNov 21, 2024 Feb 28, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of...Show more |
4Apache CanonicalDebian+1 more6Debian Linux Fusion MiddlewareManaged File Transfer+3 moreNov 21, 2024 Feb 23, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security cons...Show more |
6Apache CanonicalDebian+3 more197 Mode Transition Tool Agile Engineering Data ManagementAgile Plm+16 moreApr 21, 2026 Apr 6, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX p...Show more |