Search CVE reports
11 – 20 of 122 results
Some fixes available 5 of 9
Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a...
5 affected packages
tomcat10, tomcat6, tomcat7, tomcat8, tomcat9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat10 | Fixed | Not in release | Not in release | — |
tomcat6 | Not in release | Not in release | Not in release | — |
tomcat7 | Not in release | Not in release | Not in release | Not affected |
tomcat8 | Not in release | Not in release | Not in release | Not affected |
tomcat9 | Fixed | Fixed | Ignored | Ignored |
Some fixes available 8 of 10
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2...
5 affected packages
tomcat6, tomcat7, tomcat8, tomcat10, tomcat9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat6 | Not in release | Not in release | Not in release | — |
tomcat7 | Not in release | Not in release | Not in release | Not affected |
tomcat8 | Not in release | Not in release | Not in release | Fixed |
tomcat10 | Fixed | Not in release | Not in release | — |
tomcat9 | Fixed | Fixed | Fixed | Fixed |
Some fixes available 8 of 14
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from...
5 affected packages
tomcat6, tomcat7, tomcat8, tomcat9, tomcat10
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat6 | Not in release | Not in release | Not in release | — |
tomcat7 | Not in release | Not in release | Not in release | Needs evaluation |
tomcat8 | Not in release | Not in release | Not in release | Fixed |
tomcat9 | Fixed | Fixed | Fixed | Fixed |
tomcat10 | Fixed | Not in release | Not in release | — |
Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root
5 affected packages
tomcat6, tomcat7, tomcat8, tomcat10, tomcat9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat6 | Not in release | Not in release | Not in release | — |
tomcat7 | Not in release | Not in release | Not in release | Not affected |
tomcat8 | Not in release | Not in release | Not in release | Not affected |
tomcat10 | Not affected | Not in release | Not in release | — |
tomcat9 | Not affected | Not affected | Not affected | Not affected |
Some fixes available 3 of 13
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Users are recommended to upgrade to version...
5 affected packages
tomcat6, tomcat7, tomcat8, tomcat9, tomcat10
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat6 | Not in release | Not in release | Not in release | Not in release |
tomcat7 | Not in release | Not in release | Not in release | Needs evaluation |
tomcat8 | Not in release | Not in release | Not in release | Fixed |
tomcat9 | Not affected | Not affected | Fixed | Fixed |
tomcat10 | Not affected | Not in release | Not in release | Not in release |
Some fixes available 3 of 13
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from...
4 affected packages
tomcat6, tomcat7, tomcat8, tomcat9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat6 | Not in release | Not in release | Not in release | Not in release |
tomcat7 | Not in release | Not in release | Not in release | Vulnerable |
tomcat8 | Not in release | Not in release | Not in release | Vulnerable |
tomcat9 | Not affected | Fixed | Fixed | Fixed |
A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant...
4 affected packages
tomcat8, tomcat9, tomcat6, tomcat7
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat8 | Not in release | Not in release | Not in release | Not affected |
tomcat9 | Not affected | Not affected | Not affected | Not affected |
tomcat6 | Not in release | Not in release | Not in release | Not in release |
tomcat7 | Not in release | Not in release | Not in release | Not affected |
Some fixes available 4 of 6
If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not...
4 affected packages
tomcat6, tomcat7, tomcat8, tomcat9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat6 | — | Not in release | Not in release | Not in release |
tomcat7 | — | Not in release | Not in release | Not affected |
tomcat8 | — | Not in release | Not in release | Fixed |
tomcat9 | Not affected | Fixed | Fixed | Fixed |
A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if configured that way (repeatedly hitting the login page).
4 affected packages
tomcat6, tomcat9, tomcat7, tomcat8
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat6 | — | Not in release | Not in release | Not in release |
tomcat9 | Not affected | Not affected | Not affected | Not affected |
tomcat7 | — | Not in release | Not in release | Not affected |
tomcat8 | — | Not in release | Not in release | Not affected |
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS...
4 affected packages
tomcat6, tomcat7, tomcat8, tomcat9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat6 | Not in release | Not in release | Not in release | Not in release |
tomcat7 | Not in release | Not in release | Not in release | Needs evaluation |
tomcat8 | Not in release | Not in release | Not in release | Not affected |
tomcat9 | Not affected | Vulnerable | Vulnerable | Not affected |