The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a vigilance database and tools to fix them.

Computer vulnerabilities of Apache Tomcat

Apache Tomcat: information disclosure via NTFS JSP Source Code
An attacker can bypass access restrictions to data via NTFS JSP Source Code of Apache Tomcat, in order to obtain sensitive information...
CVE-2021-24122, DLA-2596-1, HPESBUX04114, openSUSE-SU-2021:0330-1, SUSE-SU-2021:0530-1, SUSE-SU-2021:0531-1, SUSE-SU-2021:0989-1, SUSE-SU-2021:1009-1, SUSE-SU-2021:14705-1, VIGILANCE-VUL-34350
Apache Tomcat: information disclosure via HTTP/2 Request Header Mix-up
An attacker can bypass access restrictions to data via HTTP/2 Request Header Mix-up of Apache Tomcat, in order to obtain sensitive information...
CERTFR-2020-AVI-792, cpuapr2021, CVE-2020-17527, DLA-2495-1, DSA-4835-1, openSUSE-SU-2021:0043-1, openSUSE-SU-2021:0081-1, SUSE-SU-2021:0031-1, SUSE-SU-2021:0040-1, SUSE-SU-2021:0041-1, SUSE-SU-2021:0042-1, VIGILANCE-VUL-34034
Apache Tomcat: information disclosure via HTTP/2 Concurrent Streams Request Mix-up
An attacker can bypass access restrictions to data via HTTP/2 Concurrent Streams Request Mix-up of Apache Tomcat, in order to obtain sensitive information...
cpuapr2021, CVE-2020-13943, DLA-2407-1, DSA-2021-001, DSA-4835-1, openSUSE-SU-2020:1799-1, openSUSE-SU-2020:1842-1, SUSE-SU-2020:2996-1, SUSE-SU-2020:3068-1, SUSE-SU-2020:3069-1, VIGILANCE-VUL-33544
Apache Tomcat: overload via WebSocket
An attacker can trigger an overload via WebSocket of Apache Tomcat, in order to trigger a denial of service...
6344075, bulletinjul2020, CERTFR-2020-AVI-626, cpuapr2021, cpujan2021, cpuoct2020, CVE-2020-13935, DLA-2286-1, DSA-2020-211, DSA-4627-1, HPESBUX04015, HPESBUX04114, openSUSE-SU-2020:1102-1, openSUSE-SU-2020:1111-1, RHSA-2020:3382-01, RHSA-2020:3383-01, RHSA-2020:4004-01, SB10332, SUSE-SU-2020:2037-1, SUSE-SU-2020:2045-1, SUSE-SU-2020:2046-1, SUSE-SU-2020:2047-1, SUSE-SU-2020:2611-1, USN-4448-1, USN-4596-1, VIGILANCE-VUL-32793
Apache Tomcat: denial of service via HTTP/2
An attacker can trigger a fatal error via HTTP/2 of Apache Tomcat, in order to trigger a denial of service...
6344075, bulletinjul2020, CERTFR-2020-AVI-626, cpuapr2021, cpujan2021, cpuoct2020, CVE-2020-13934, DLA-2286-1, DSA-2020-211, DSA-4627-1, openSUSE-SU-2020:1102-1, openSUSE-SU-2020:1111-1, SUSE-SU-2020:2037-1, SUSE-SU-2020:2045-1, SUSE-SU-2020:2046-1, SUSE-SU-2020:2047-1, USN-4596-1, VIGILANCE-VUL-32792
Apache Tomcat: overload via HTTP/2 Requests Sequence
An attacker can trigger an overload via HTTP/2 Requests Sequence of Apache Tomcat, in order to trigger a denial of service...
bulletinjul2020, CERTFR-2020-AVI-397, cpuoct2020, CVE-2020-11996, DLA-2279-1, DSA-4627-1, openSUSE-SU-2020:1051-1, openSUSE-SU-2020:1063-1, SUSE-SU-2020:1841-1, SUSE-SU-2020:1962-1, SUSE-SU-2020:1963-1, SUSE-SU-2020:1983-1, USN-4596-1, VIGILANCE-VUL-32624
Apache Tomcat: code execution via PersistenceManager
An attacker can use a vulnerability via PersistenceManager of Apache Tomcat, in order to run code...
CERTFR-2020-AVI-315, CERTFR-2020-AVI-417, cpuapr2021, cpuoct2020, CVE-2020-9484, DLA-2209-1, DLA-2217-1, DLA-2279-1, DSA-2020-161, DSA-4627-1, ESDSA16092, FEDORA-2020-ce396e7d5c, FEDORA-2020-d9169235a8, NTAP-20200528-0005, openSUSE-SU-2020:0711-1, RHSA-2020:2529-01, RHSA-2020:2530-01, SB10332, USN-4448-1, USN-4596-1, VIGILANCE-VUL-32313
Apache Tomcat: code execution via Enabled AJP Connector
An attacker can use a vulnerability via Enabled AJP Connector of Apache Tomcat, in order to run code...
bulletinapr2020, CERTFR-2020-AVI-112, cpujul2020, CVE-2020-1938, DLA-2133-1, DLA-2209-1, DSA-4673-1, DSA-4680-1, FEDORA-2020-04ac174fa9, FEDORA-2020-c870aa8378, HPESBUX04015, openSUSE-SU-2020:0345-1, openSUSE-SU-2020:0597-1, RHSA-2020:0855-01, RHSA-2020:0912-01, RHSA-2020:1478-01, RHSA-2020:1479-01, RHSA-2020:2779-01, RHSA-2020:2780-01, RHSA-2020:2781-01, RHSA-2020:2783-01, RHSA-2020:2840-01, SUSE-SU-2020:0598-1, SUSE-SU-2020:0631-1, SUSE-SU-2020:0632-1, SUSE-SU-2020:0725-1, SUSE-SU-2020:1111-1, SUSE-SU-2020:1126-1, SUSE-SU-2020:1272-1, SUSE-SU-2020:14342-1, VIGILANCE-VUL-31664
Apache Tomcat: information disclosure via Reverse Proxy Transfer-Encoding End-of-line HTTP Request Smuggling
An attacker can bypass access restrictions to data via Reverse Proxy Transfer-Encoding End-of-line HTTP Request Smuggling of Apache Tomcat, in order to obtain sensitive information...
bulletinapr2020, cpujul2020, CVE-2020-1935, DLA-2133-1, DLA-2209-1, DSA-4673-1, DSA-4680-1, HPESBUX04015, openSUSE-SU-2020:0345-1, RHSA-2020:5020-01, RHSA-2021:0882-01, RHSA-2021:1030-01, SUSE-SU-2020:0598-1, SUSE-SU-2020:0631-1, SUSE-SU-2020:0632-1, SUSE-SU-2020:2611-1, USN-4448-1, VIGILANCE-VUL-31663
Apache Tomcat: information disclosure via Reverse Proxy Transfer-Encoding Header HTTP Request Smuggling
An attacker can bypass access restrictions to data via Reverse Proxy Transfer-Encoding Header HTTP Request Smuggling of Apache Tomcat, in order to obtain sensitive information...
bulletinapr2020, cpujul2020, CVE-2019-17569, DLA-2133-1, DSA-4673-1, DSA-4680-1, HPESBUX04015, openSUSE-SU-2020:0345-1, SUSE-SU-2020:0598-1, SUSE-SU-2020:0631-1, SUSE-SU-2020:0632-1, VIGILANCE-VUL-31662
Our database contains other pages. You can request a free trial to read them.

Display information about Apache Tomcat: