Known vulnerabilities in Apache Tomcat 8.5.43

Software: Apache Tomcat
Version: 8.5.43
Software CPE: cpe:2.3:a:apache_foundation:apache_tomcat:*:*:*:*:*:*:*:*
Total vulnerabilities: 35
Public exploits: 11
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Apache Tomcat version 8.5.43 Apache Tomcat 8.5.43 is affected by 35 vulnerabilities: 3 high, 26 medium, 6 low Critical High Medium Low

Vulnerabilities (35)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU87510 - Improper input validation
CVE-2024-24549
CWE-20 Medium
Public exploit available
No
8.5.99, 9.0.86, 10.1.19, 11.0.0-M17 13.03.2024 SB2024031386
SB2024031879
SB2024031880
and 64 more
#VU87509 - Resource exhaustion
CVE-2024-23672
CWE-400 Medium
No
No
8.5.99, 9.0.86, 10.1.19, 11.0.0-M17 13.03.2024 SB2024031386
SB2024032821
SB2024032824
and 49 more
#VU85619 - Exposure of sensitive information to an unauthorized actor
CVE-2024-21733
CWE-200 Medium
Public exploit available
No
8.5.64, 9.0.44 19.01.2024 SB2024011929
SB2024020819
SB2024030424
and 9 more
#VU83533 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-46589
CWE-444 Medium
No
No
8.5.96, 9.0.83, 10.1.16, 11.0.0-M11 28.11.2023 SB2023112846
SB2023121851
SB2023122831
and 78 more
#VU81800 - Resource Management Errors
CVE-2023-42795
CWE-399 Medium
No
No
8.5.94, 9.0.81, 10.1.14, 11.0.0-M12 10.10.2023 SB2023101084
SB2023101122
SB2023101123
and 47 more
#VU81799 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-45648
CWE-444 Medium
No
No
8.5.94, 9.0.81, 10.1.14, 11.0.0-M12 10.10.2023 SB2023101084
SB2023101122
SB2023101123
and 47 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Public exploit available
Exploited
8.5.94, 9.0.81, 10.1.14, 11.0.0-M12 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 648 more
#VU80089 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2023-41080
CWE-601 Medium
Public exploit available
No
8.5.93, 9.0.80, 10.1.13, 11.0.0-M11 29.08.2023 SB2023082924
SB2023100565
SB2023101122
and 51 more
#VU76417 - Allocation of Resources Without Limits or Throttling
CVE-2023-28709
CWE-770 Medium
No
No
8.5.88, 9.0.74, 10.1.8, 11.0.0-M5 22.05.2023 SB2023052235
SB2023053003
SB2023053052
and 35 more
#VU73957 - Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2023-28708
CWE-614 Low
No
No
8.5.86, 9.0.72, 10.1.6, 11.0.0-M3 22.03.2023 SB2023032237
SB2023032939
SB2023032945
and 53 more
#VU72427 - Allocation of Resources Without Limits or Throttling
CVE-2023-24998
CWE-770 Medium
Public exploit available
No
8.5.85, 9.0.71, 10.1.5, 11.0.0-M3 20.02.2023 SB2023022046
SB2023022047
SB2023030917
and 202 more
#VU68859 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-42252
CWE-444 Medium
No
No
8.5.83, 9.0.68, 10.0.27, 10.1.1 31.10.2022 SB2022103146
SB2022112324
SB2022112533
and 43 more
#VU67714 - Exposure of sensitive information to an unauthorized actor
CVE-2021-43980
CWE-200 Low
No
No
8.5.78, 9.0.62, 10.0.20, 10.1.0-M14 28.09.2022 SB2022092818
SB2022103001
SB2022111642
and 20 more
#VU64627 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-34305
CWE-79 Medium
Public exploit available
No
8.5.82, 9.0.65, 10.0.23, 10.1.0-M17 23.06.2022 SB2022062338
SB2022071177
SB2022071801
and 26 more
#VU63299 - Error Handling
CVE-2022-25762
CWE-388 Medium
No
No
8.5.76, 9.0.21 17.05.2022 SB2022051715
SB2022071173
SB2022072094
and 14 more
#VU63225 - Data Handling
CVE-2022-29885
CWE-19 Low
Public exploit available
No
8.5.79, 9.0.63, 10.0.21, 10.1.0-M15 16.05.2022 SB2022051612
SB2022072044
SB20220720107
and 19 more
#VU60079 - Permissions, Privileges, and Access Controls
CVE-2022-23181
CWE-264 Low
No
No
8.5.75, 9.0.58, 10.0.15, 10.1.0-M10 27.01.2022 SB2022012708
SB2022030854
SB2022041951
and 25 more
#VU57389 - Resource exhaustion
CVE-2021-42340
CWE-400 Medium
No
No
8.5.72, 9.0.54, 10.0.12, 10.1.0-M6 15.10.2021 SB2021101507
SB2021110507
SB2021111711
and 28 more
#VU56634 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2021-41079
CWE-835 Medium
No
No
8.5.64, 9.0.44, 10.0.4 15.09.2021 SB2021091527
SB2021100721
SB2021101512
and 16 more
#VU55423 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-33037
CWE-444 Medium
No
No
8.5.68, 9.0.48, 10.0.7 29.07.2021 SB2021072907
SB2021080807
SB2021080808
and 30 more


Showing elements 1 - 20 out of 35