Search CVE reports
21 – 30 of 122 results
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0...
4 affected packages
tomcat9, tomcat6, tomcat7, tomcat8
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat9 | Not affected | Vulnerable | Vulnerable | Vulnerable |
tomcat6 | — | Not in release | Not in release | Not in release |
tomcat7 | — | Not in release | Not in release | Needs evaluation |
tomcat8 | — | Not in release | Not in release | Vulnerable |
Some fixes available 3 of 8
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be...
4 affected packages
tomcat6, tomcat7, tomcat8, tomcat9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat6 | Not in release | Not in release | Not in release | Not in release |
tomcat7 | Not in release | Not in release | Not in release | Not affected |
tomcat8 | Not in release | Not in release | Not in release | Fixed |
tomcat9 | Not affected | Not affected | Fixed | Fixed |
Some fixes available 2 of 16
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a...
4 affected packages
tomcat6, tomcat7, tomcat8, tomcat9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat6 | Not in release | Not in release | Not in release | Not in release |
tomcat7 | Not in release | Not in release | Not in release | Vulnerable |
tomcat8 | Not in release | Not in release | Not in release | Vulnerable |
tomcat9 | Not affected | Not affected | Fixed | Fixed |
Some fixes available 2 of 16
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat...
4 affected packages
tomcat6, tomcat7, tomcat8, tomcat9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat6 | Not in release | Not in release | Not in release | Not in release |
tomcat7 | Not in release | Not in release | Not in release | Vulnerable |
tomcat8 | Not in release | Not in release | Not in release | Vulnerable |
tomcat9 | Not affected | Not affected | Fixed | Fixed |
A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the...
4 affected packages
tomcat6, tomcat7, tomcat8, tomcat9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat6 | Not in release | Not in release | Not in release | Not in release |
tomcat7 | Not in release | Not in release | Not in release | Not affected |
tomcat8 | Not in release | Not in release | Not in release | Not affected |
tomcat9 | Not affected | Not affected | Not affected | Not affected |
Some fixes available 5 of 16
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat...
4 affected packages
tomcat6, tomcat7, tomcat8, tomcat9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat6 | Not in release | Not in release | Not in release | Not in release |
tomcat7 | Not in release | Not in release | Not in release | Fixed |
tomcat8 | Not in release | Not in release | Not in release | Vulnerable |
tomcat9 | Not affected | Not affected | Fixed | Fixed |
Some fixes available 3 of 9
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another...
4 affected packages
tomcat6, tomcat7, tomcat8, tomcat9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat6 | Not in release | Not in release | Not in release | Not in release |
tomcat7 | Not in release | Not in release | Not in release | Not affected |
tomcat8 | Not in release | Not in release | Not in release | Fixed |
tomcat9 | Not affected | Not affected | Fixed | Fixed |
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in...
4 affected packages
tomcat6, tomcat7, tomcat8, tomcat9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat6 | Not in release | Not in release | Not in release | Not in release |
tomcat7 | Not in release | Not in release | Not in release | Vulnerable |
tomcat8 | Not in release | Not in release | Not in release | Vulnerable |
tomcat9 | Not affected | Not affected | Vulnerable | Vulnerable |
Some fixes available 7 of 8
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured...
3 affected packages
tomcat7, tomcat8, tomcat9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat7 | Not in release | Not in release | Not in release | Fixed |
tomcat8 | Not in release | Not in release | Not in release | Fixed |
tomcat9 | Not affected | Not affected | Fixed | Fixed |
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such...
3 affected packages
tomcat7, tomcat8, tomcat9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tomcat7 | Not in release | Not in release | Not in release | Ignored |
tomcat8 | Not in release | Not in release | Not in release | Ignored |
tomcat9 | Not affected | Not affected | Not affected | Ignored |