<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apache Tomcat (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/tomcat.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/tomcat-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apache Tomcat (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-44257 – efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44257</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44257</guid>
    <pubDate>Tue, 12 May 2026 22:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44257</strong></p>
  <p>efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk using new File(baseDir, zipEntry.getName()) with no canonical-path check. An entry name such as ../../../pwned.jsp escapes the intended extraction directory and lands anywhere the Tomcat process can write — including the servlet context root. Combined with the framework's multipart…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44257">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-43515 – Improper Authorization vulnerability when multiple method constraints define an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43515</guid>
    <pubDate>Tue, 12 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-43515</strong></p>
  <p>Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.  Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which f…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43513 – Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache To...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43513</guid>
    <pubDate>Tue, 12 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43513</strong></p>
  <p>Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected.  Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-178</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-43512 – DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43512</guid>
    <pubDate>Tue, 12 May 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-43512</strong></p>
  <p>DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0. Older unsupported versions any also be affect  Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-592</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42498 – Exposure of HTTP Authentication Header to unexpected hosts during WebSocket auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42498</guid>
    <pubDate>Tue, 12 May 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42498</strong></p>
  <p>Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109.  Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the iss…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41293 – Improper Input Validation vulnerability in Apache Tomcat.

This issue affects Ap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41293</guid>
    <pubDate>Tue, 12 May 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41293</strong></p>
  <p>Improper Input Validation vulnerability in Apache Tomcat.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions may also be affected.  Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41284 – Allocation of Resources Without Limits or Throttling vulnerability in Apache Tom...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41284</guid>
    <pubDate>Tue, 12 May 2026 16:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41284</strong></p>
  <p>Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117. Older, unsupported versions may also be affected.  Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40075 – OpenMRS Core is an open source electronic medical record system platform. In ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40075</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40075</guid>
    <pubDate>Tue, 05 May 2026 22:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40075</strong></p>
  <p>OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openmrs/moduleResources/{moduleid}` endpoint is vulnerable to a path traversal attack. The ModuleResourcesServlet constructs a filesystem path from user-controlled input without performing path boundary validation — the getFile() method concatenates the u…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40075">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34487 – Insertion of Sensitive Information into Log File vulnerability in the cloud memb...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34487</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34487</guid>
    <pubDate>Thu, 09 Apr 2026 20:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34487</strong></p>
  <p>Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116.  Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34487">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34486 – Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34486</guid>
    <pubDate>Thu, 09 Apr 2026 20:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34486</strong></p>
  <p>Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.  This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.  Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34486">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34483 – Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34483</guid>
    <pubDate>Thu, 09 Apr 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34483</strong></p>
  <p>Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116.  Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29146 – Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29146</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29146</guid>
    <pubDate>Thu, 09 Apr 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29146</strong></p>
  <p>Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.  Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29146">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-29145 – CLIENT_CERT authentication does not fail as expected for some scenarios when sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29145</guid>
    <pubDate>Thu, 09 Apr 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-29145</strong></p>
  <p>CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 thro…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29129 – Configured cipher preference order not preserved vulnerability in Apache Tomcat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29129</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29129</guid>
    <pubDate>Thu, 09 Apr 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29129</strong></p>
  <p>Configured cipher preference order not preserved vulnerability in Apache Tomcat.  This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115.  Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29129">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24880 – Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24880</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24880</guid>
    <pubDate>Thu, 09 Apr 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24880</strong></p>
  <p>Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other, unsupported versions may also be affected.  Users are recommended…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24880">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28228 – OpenOlat is an open source web-based e-learning platform for teaching, learning,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28228</guid>
    <pubDate>Mon, 30 Mar 2026 21:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28228</strong></p>
  <p>OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. Prior to versions 19.1.31, 20.1.18, and 20.2.5, an authenticated user with the Author role can inject Velocity directives into a reminder email template. When the reminder is processed (either triggered manually or via the daily cron job), the injected directives are evaluated server-sid…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-20026 – ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache To...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-20026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-20026</guid>
    <pubDate>Mon, 16 Mar 2026 14:17:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-20026</strong></p>
  <p>ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. Attackers can authenticate with hardcoded credentials stored in tomcat-users.xml to upload malicious WAR archives containing JSP applications and execute arbitrary code with SYSTEM privileges.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-20026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-11165 – A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11165</guid>
    <pubDate>Tue, 24 Feb 2026 09:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-11165</strong></p>
  <p>A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileges to bypass class and package restrictions enforced by SecureUberspectorImpl.  By dynamically modifying the Velocity engine’s runtime configuration and reinitializing its Uberspect, a malicious actor can remove the introspector.restrict.classes and introspec…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24734 – Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat.
...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24734</guid>
    <pubDate>Tue, 17 Feb 2026 19:21:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24734</strong></p>
  <p>Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat.  When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed.  This issue affects Apache Tomcat Native:  from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11;…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-66614 – Improper Input Validation vulnerability.

This issue affects Apache Tomcat: from...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66614</guid>
    <pubDate>Tue, 17 Feb 2026 19:21:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-66614</strong></p>
  <p>Improper Input Validation vulnerability.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112.  The following versions were EOL at the time the CVE was created but are  known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate that the host name provided via the SNI  extensi…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-63690 – In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63690</guid>
    <pubDate>Fri, 07 Nov 2025 16:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-63690</strong></p>
  <p>In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management module, it is possible to execute any Java class with a parameterless constructor and its methods with parameter type String through reflection. At this time, the eval method in Tomcat's built-in class jakarta.el.ELProcessor can be used to execute commands, leadi…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-470</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-55754 – Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55754</guid>
    <pubDate>Mon, 27 Oct 2025 18:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-55754</strong></p>
  <p>Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat.  Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-150</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55752 – Relative Path Traversal vulnerability in Apache Tomcat.

The fix for bug 60013 i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55752</guid>
    <pubDate>Mon, 27 Oct 2025 18:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55752</strong></p>
  <p>Relative Path Traversal vulnerability in Apache Tomcat.  The fix for bug 60013 introduced a regression where the       rewritten URL was normalized before it was decoded. This introduced the       possibility that, for rewrite rules that rewrite query parameters to the       URL, an attacker could manipulate the request URI to bypass security       constraints including the protection for /WEB-IN…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48989 – Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48989</guid>
    <pubDate>Wed, 13 Aug 2025 13:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48989</strong></p>
  <p>Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected.  Users are recommended to upgrade to one of versions 11.0.10, 10.1.44 or 9.0.108 which fix the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53506 – Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 cl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53506</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53506</guid>
    <pubDate>Thu, 10 Jul 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53506</strong></p>
  <p>Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are  known to b…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53506">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-52520 – For some unlikely configurations of multipart upload, an Integer Overflow vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52520</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52520</guid>
    <pubDate>Thu, 10 Jul 2025 19:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-52520</strong></p>
  <p>For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are  known to be affected: 8.5.0 through 8.5.10…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52520">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-52434 – Concurrent Execution using Shared Resource with Improper Synchronization ('Race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52434</guid>
    <pubDate>Thu, 10 Jul 2025 19:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-52434</strong></p>
  <p>Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.  This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are  known to be aff…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49125 – Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49125</guid>
    <pubDate>Mon, 16 Jun 2025 15:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49125</strong></p>
  <p>Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowing those security constraints to be bypassed.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49124 – Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. Duri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49124</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49124</guid>
    <pubDate>Mon, 16 Jun 2025 15:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49124</strong></p>
  <p>Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. The following versions were EOL at the time the CVE was created but are  known to be affected: 8.…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49124">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48988 – Allocation of Resources Without Limits or Throttling vulnerability in Apache Tom...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48988</guid>
    <pubDate>Mon, 16 Jun 2025 15:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48988</strong></p>
  <p>Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are  known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions  may also be affected.   Users are recomm…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46701 – Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46701</guid>
    <pubDate>Thu, 29 May 2025 19:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46701</strong></p>
  <p>Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104. The following versions were EOL at the time the CVE was…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-178</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-31651 – Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31651</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31651</guid>
    <pubDate>Mon, 28 Apr 2025 20:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-31651</strong></p>
  <p>Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible  for a specially crafted request to bypass some rewrite rules. If those  rewrite rules effectively enforced security constraints, those  constraints could be bypassed.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, f…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31651">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31650 – Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handli...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31650</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31650</guid>
    <pubDate>Mon, 28 Apr 2025 20:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31650</strong></p>
  <p>Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service.  This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-459</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31650">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-24813 – Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24813</guid>
    <pubDate>Mon, 10 Mar 2025 17:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-24813</strong></p>
  <p>Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was create…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-44</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24813">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-56337 – Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56337</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56337</guid>
    <pubDate>Fri, 20 Dec 2024 16:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-56337</strong></p>
  <p>Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are  known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions  may also be affected.   The mitigation for C…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56337">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-50379 – Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-50379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-50379</guid>
    <pubDate>Tue, 17 Dec 2024 13:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-50379</strong></p>
  <p>Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration).  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97.  The following versions were EOL at the time…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-52316 – Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configure...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52316</guid>
    <pubDate>Mon, 18 Nov 2024 12:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-52316</strong></p>
  <p>Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no know…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-391</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38286 – Allocation of Resources Without Limits or Throttling vulnerability in Apache Tom...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38286</guid>
    <pubDate>Thu, 07 Nov 2024 08:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38286</strong></p>
  <p>Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89.   The following versions were EOL at the time the CVE was created but are  known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Other EOL versions may also be affec…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22029 – Insecure permissions in the packaging of tomcat allow local users that win a rac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22029</guid>
    <pubDate>Wed, 16 Oct 2024 14:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22029</strong></p>
  <p>Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38816 – Applications serving static resources through the functional web frameworks WebM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38816</guid>
    <pubDate>Fri, 13 Sep 2024 06:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38816</strong></p>
  <p>Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.  Specifically, an application is vulnerable when both of the following are true:    *  th…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34750 – Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34750</guid>
    <pubDate>Wed, 03 Jul 2024 20:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34750</strong></p>
  <p>Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24749 – GeoServer is an open source server that allows users to share and edit geospatia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24749</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24749</guid>
    <pubDate>Mon, 01 Jul 2024 14:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24749</strong></p>
  <p>GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.24.3, if GeoServer is deployed in the Windows operating system using an Apache Tomcat web application server, it is possible to bypass existing input validation in the GeoWebCache ByteStreamController class and read arbitrary classpath resources with specific file name extensions…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24749">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5246 – NETGEAR ProSAFE Network Management System Tomcat Remote Code Execution Vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5246</guid>
    <pubDate>Thu, 23 May 2024 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5246</strong></p>
  <p>NETGEAR ProSAFE Network Management System Tomcat Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability.  The specific flaw exists within the product installer. The issue results from the use of a vulnerable version of…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-2632 – A Information Exposure Vulnerability has been found on Meta4 HR. This vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2632</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2632</guid>
    <pubDate>Tue, 19 Mar 2024 12:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-2632</strong></p>
  <p>A Information Exposure Vulnerability has been found on Meta4 HR. This vulnerability allows an attacker to obtain a lot of information about the application such as the variables set in the process, the Tomcat versions, library versions and underlying operation system via HTTP GET '/sitetest/english/dumpenv.jsp'.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2632">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24549 – Denial of Service due to improper input validation vulnerability for HTTP/2 requ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24549</guid>
    <pubDate>Wed, 13 Mar 2024 16:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24549</strong></p>
  <p>Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, f…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49694 – A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Net...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49694</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49694</guid>
    <pubDate>Wed, 29 Nov 2023 23:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49694</strong></p>
  <p>A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in a Tomcat web application directory. The user can then execute the JSP files under the security context of SYSTEM.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49694">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46589 – Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46589</guid>
    <pubDate>Tue, 28 Nov 2023 16:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46589</strong></p>
  <p>Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single  request as multiple requests leading to the possibility of request  smug…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46589">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-47246 – In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to cod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47246</guid>
    <pubDate>Fri, 10 Nov 2023 06:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-47246</strong></p>
  <p>In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-4760 – In Eclipse RAP versions from 3.0.0 up to and including 3.25.0, Remote Code Execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4760</guid>
    <pubDate>Thu, 21 Sep 2023 08:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-4760</strong></p>
  <p>In Eclipse RAP versions from 3.0.0 up to and including 3.25.0, Remote Code Execution is possible on Windows when using the FileUpload component.       The reason for this is a not completely secure extraction of the file name in the FileUploadProcessor.stripFileName(String name) method. As soon as this finds a / in the path, everything before it is removed, but potentially \ (backslashes) coming…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41081 – Important: Authentication Bypass CVE-2023-41081

The mod_jk component of Apache ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41081</guid>
    <pubDate>Wed, 13 Sep 2023 10:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41081</strong></p>
  <p>Important: Authentication Bypass CVE-2023-41081  The mod_jk component of Apache Tomcat Connectors in some circumstances, such as when a configuration included "JkOptions +ForwardDirectories" but the configuration did not       provide explicit mounts for all possible proxied requests, mod_jk would       use an implicit mapping and map the request to the first defined worker. Such an implicit mapp…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-34128 – Tomcat application credentials are hardcoded in SonicWall GMS and Analytics conf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34128</guid>
    <pubDate>Thu, 13 Jul 2023 01:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-34128</strong></p>
  <p>Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-260</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-34981 – A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34981</guid>
    <pubDate>Wed, 21 Jun 2023 11:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-34981</strong></p>
  <p>A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an information leak.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-28709 – The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28709</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28709</guid>
    <pubDate>Mon, 22 May 2023 11:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-28709</strong></p>
  <p>The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP       connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was       submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uplo…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-193</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28709">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-29517 – XWiki Platform is a generic wiki platform offering runtime services for applicat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29517</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29517</guid>
    <pubDate>Wed, 19 Apr 2023 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-29517</strong></p>
  <p>XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The office document viewer macro was allowing anyone to see any file content from the hosting server, provided that the office server was connected and depending on the permissions of the user running the servlet engine (e.g. tomcat) running XWiki. The same vulnerability also allowed to perfor…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29517">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0100 – In Eclipse BIRT, starting from version 2.6.2, the default configuration allowed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0100</guid>
    <pubDate>Wed, 15 Mar 2023 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0100</strong></p>
  <p>In Eclipse BIRT, starting from version 2.6.2, the default configuration allowed to retrieve a report from the same host using an absolute HTTP path for the report parameter (e.g. __report=http://xyz.com/report.rptdesign). If the host indicated in the __report parameter matched the HTTP Host header value, the report would be retrieved. However, the Host header can be tampered with on some configur…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25544 – Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclos...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25544</guid>
    <pubDate>Wed, 01 Mar 2023 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25544</strong></p>
  <p>Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-45143 – The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45143</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45143</guid>
    <pubDate>Tue, 03 Jan 2023 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-45143</strong></p>
  <p>The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45143">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42252 – If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42252</guid>
    <pubDate>Tue, 01 Nov 2022 09:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42252</strong></p>
  <p>If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31195 – DSpace open source software is a repository application which provides durable a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31195</guid>
    <pubDate>Mon, 01 Aug 2022 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31195</strong></p>
  <p>DSpace open source software is a repository application which provides durable access to digital resources. In affected versions the ItemImportServiceImpl is vulnerable to a path traversal vulnerability. This means a malicious SAF (simple archive format) package could cause a file/directory to be created anywhere the Tomcat/DSpace user can write to on the server. However, this path traversal vuln…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31194 – DSpace open source software is a repository application which provides durable a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31194</guid>
    <pubDate>Mon, 01 Aug 2022 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31194</strong></p>
  <p>DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI resumable upload implementations in SubmissionController and FileUploadRequest are vulnerable to multiple path traversal attacks, allowing an attacker to create files/directories anywhere on the server writable by the Tomcat/DSpace user,…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-30929 – Mini-Tmall v1.0 is vulnerable to Insecure Permissions via tomcat-embed-jasper.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-30929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-30929</guid>
    <pubDate>Wed, 06 Jul 2022 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-30929</strong></p>
  <p>Mini-Tmall v1.0 is vulnerable to Insecure Permissions via tomcat-embed-jasper.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-25762 – If a web application sends a WebSocket message concurrently with the WebSocket c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25762</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25762</guid>
    <pubDate>Fri, 13 May 2022 08:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-25762</strong></p>
  <p>If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25762">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-29885 – The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29885</guid>
    <pubDate>Thu, 12 May 2022 08:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-29885</strong></p>
  <p>The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running ov…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-22965 – A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22965</guid>
    <pubDate>Fri, 01 Apr 2022 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-22965</strong></p>
  <p>A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45877 – Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45877</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45877</guid>
    <pubDate>Mon, 21 Mar 2022 11:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45877</strong></p>
  <p>Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, which allows attackers to gain authorized access and control the tomcat completely on port 8000 in the tomcat manger page.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45877">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-45968 – An issue was discovered in xmppserver jar in the XMPP Server component of the JI...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45968</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45968</guid>
    <pubDate>Fri, 18 Mar 2022 05:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-45968</strong></p>
  <p>An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and in other products). An endpoint in the backend Tomcat server of the Pascom allows SSRF, a related issue to CVE-2019-18394.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45968">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45967 – An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configurat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45967</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45967</guid>
    <pubDate>Fri, 18 Mar 2022 05:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45967</strong></p>
  <p>An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45967">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-26520 – In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26520</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26520</guid>
    <pubDate>Thu, 10 Mar 2022 17:47:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-26520</strong></p>
  <p>In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. NOTE: the vendor's position is that there is no pgjdbc vulnerability; instead, it is a vu…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26520">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23612 – OpenMRS is a patient-based medical record system focusing on giving providers a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23612</guid>
    <pubDate>Tue, 22 Feb 2022 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23612</strong></p>
  <p>OpenMRS is a patient-based medical record system focusing on giving providers a free customizable electronic medical record system. Affected versions are subject to arbitrary file exfiltration due to failure to sanitize request when satisfying GET requests for `/images` & `/initfilter/scripts`. This can allow an attacker to access any file on a system running OpenMRS that is accessible to the use…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23181 – The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23181</guid>
    <pubDate>Thu, 27 Jan 2022 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23181</strong></p>
  <p>The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-40348 – Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection. rh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-40348</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-40348</guid>
    <pubDate>Mon, 01 Nov 2021 05:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-40348</strong></p>
  <p>Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection. rhn-config-satellite.pl doesn't sanitize the configuration filename used to append Spacewalk-specific key-value pair. The script is intended to be run by the tomcat user account with Sudo, according to the installation setup. This can lead to the ability of an attacker to use --option to append arbitrary code to a root-…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-40348">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-42340 – The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-42340</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-42340</guid>
    <pubDate>Thu, 14 Oct 2021 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-42340</strong></p>
  <p>The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryE…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-42340">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41079 – Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did no...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41079</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41079</guid>
    <pubDate>Thu, 16 Sep 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41079</strong></p>
  <p>Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41079">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39180 – OpenOLAT is a web-based learning management system (LMS). A path traversal vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39180</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39180</guid>
    <pubDate>Tue, 31 Aug 2021 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39180</strong></p>
  <p>OpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15.3.18, 15.5.3, and 16.0.0. Using a specially prepared ZIP file, it is possible to overwrite any file that is writable by the application server user (e.g. the tomcat user). Depending on the configuration this can be limited to files of the OpenOlat user data directory, however, i…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39180">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-32588 – A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32588</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32588</guid>
    <pubDate>Wed, 18 Aug 2021 22:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-32588</strong></p>
  <p>A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 and below, versions 5.1.x and 5.0.x may allow a remote and unauthenticated attacker to execute unauthorized commands as root by uploading and deploying malicious web application archive files using the default hard-coded Tomcat Manager username and password.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32588">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-30639 – A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-30639</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-30639</guid>
    <pubDate>Mon, 12 Jul 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-30639</strong></p>
  <p>A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the Request object was not reset between requests. This meant that once a non-blocking I/O error occurred, all future requests handled by that request object would fail. User…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30639">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25329 – The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25329</guid>
    <pubDate>Mon, 01 Mar 2021 12:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25329</strong></p>
  <p>The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25329">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25122 – When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25122</guid>
    <pubDate>Mon, 01 Mar 2021 12:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25122</strong></p>
  <p>When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-5805 – In Marvell QConvergeConsole GUI &lt;= 5.5.0.74, credentials are stored in cleartext...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5805</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5805</guid>
    <pubDate>Fri, 08 Jan 2021 16:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-5805</strong></p>
  <p>In Marvell QConvergeConsole GUI <= 5.5.0.74, credentials are stored in cleartext in tomcat-users.xml. OS-level users on the QCC host who are not authorized to use QCC may use the plaintext credentials to login to QCC.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5805">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36182 – FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36182</guid>
    <pubDate>Thu, 07 Jan 2021 00:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36182</strong></p>
  <p>FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36187 – FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36187</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36187</guid>
    <pubDate>Wed, 06 Jan 2021 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36187</strong></p>
  <p>FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36187">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36186 – FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36186</guid>
    <pubDate>Wed, 06 Jan 2021 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36186</strong></p>
  <p>FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36185 – FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36185</guid>
    <pubDate>Wed, 06 Jan 2021 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36185</strong></p>
  <p>FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36184 – FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36184</guid>
    <pubDate>Wed, 06 Jan 2021 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36184</strong></p>
  <p>FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36181 – FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36181</guid>
    <pubDate>Wed, 06 Jan 2021 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36181</strong></p>
  <p>FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-17527 – While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-17527</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-17527</guid>
    <pubDate>Thu, 03 Dec 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-17527</strong></p>
  <p>While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that inform…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-17527">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-26510 – Airleader Master &lt;= 6.21 devices have default credentials that can be used to ac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26510</guid>
    <pubDate>Mon, 16 Nov 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-26510</strong></p>
  <p>Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for deployment of a new .war file, with resultant remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-17388 – This vulnerability allows remote attackers to execute arbitrary code on affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-17388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-17388</guid>
    <pubDate>Tue, 25 Aug 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-17388</strong></p>
  <p>This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Tomcat configuration file. The issue results from the lack of proper restriction to the Tomcat admin console…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-749</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-17388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15124 – In Goobi Viewer Core before version 4.8.3, a path traversal vulnerability allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15124</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15124</guid>
    <pubDate>Wed, 22 Jul 2020 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15124</strong></p>
  <p>In Goobi Viewer Core before version 4.8.3, a path traversal vulnerability allows for remote attackers to access files on the server via the application. This is limited to files accessible to the application server user, eg. tomcat, but can potentially lead to the disclosure of sensitive information. The vulnerability has been fixed in version 4.8.3</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15124">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13935 – The payload length in a WebSocket frame was not correctly validated in Apache To...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13935</guid>
    <pubDate>Tue, 14 Jul 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13935</strong></p>
  <p>The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13934 – An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13934</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13934</guid>
    <pubDate>Tue, 14 Jul 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13934</strong></p>
  <p>An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13934">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20419 – Affected versions of Atlassian Jira Server and Data Center allow remote attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20419</guid>
    <pubDate>Fri, 03 Jul 2020 02:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20419</strong></p>
  <p>Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hijacking vulnerability in Tomcat. The affected versions are before version 8.5.5, and from version 8.6.0 before 8.7.2.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8022 – A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8022</guid>
    <pubDate>Mon, 29 Jun 2020 09:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8022</strong></p>
  <p>A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux Enterprise Server 12-SP3-LTSS, SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterpr…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11996 – A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11996</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11996</guid>
    <pubDate>Fri, 26 Jun 2020 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11996</strong></p>
  <p>A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11996">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9484 – When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9484</guid>
    <pubDate>Wed, 20 May 2020 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9484</strong></p>
  <p>When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a Secur…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-1938 – When using the Apache JServ Protocol (AJP), care must be taken when trusting inc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1938</guid>
    <pubDate>Mon, 24 Feb 2020 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-1938</strong></p>
  <p>When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomc…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20406 – The usage of Tomcat in Confluence on the Microsoft Windows operating system befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20406</guid>
    <pubDate>Thu, 06 Feb 2020 03:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20406</strong></p>
  <p>The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable to inject code & escalate their privileges via a DLL hijacking vulnerability.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20400 – The usage of Tomcat in Jira before version 8.5.2 allows local attackers with per...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20400</guid>
    <pubDate>Thu, 06 Feb 2020 03:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20400</strong></p>
  <p>The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hijacking vulnerability.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-6754 – dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-6754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-6754</guid>
    <pubDate>Wed, 05 Feb 2020 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-6754</strong></p>
  <p>dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g., .jsp files) into /webapps/ROOT/assets/tmp_upload, which can lead to remote command execution (with the permissions of t…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-6754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14768 – An Arbitrary File Upload issue in the file browser of DIMO YellowBox CRM before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14768</guid>
    <pubDate>Tue, 21 Jan 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14768</strong></p>
  <p>An Arbitrary File Upload issue in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to deploy a new WebApp WAR file to the Tomcat server via Path Traversal, allowing remote code execution with SYSTEM privileges.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14768">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
