Known vulnerabilities in Apache Tomcat 7.0.36

Software: Apache Tomcat
Version: 7.0.36
Software CPE: cpe:2.3:a:apache_foundation:apache_tomcat:*:*:*:*:*:*:*:*
Total vulnerabilities: 32
Public exploits: 9
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Apache Tomcat version 7.0.36 Apache Tomcat 7.0.36 is affected by 32 vulnerabilities: 6 high, 9 medium, 17 low Critical High Medium Low

Vulnerabilities (32)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU55417 - Improper Authentication
CVE-2021-30640
CWE-287 Medium
No
No
7.0.109, 8.5.66, 9.0.46, 10.0.6 29.07.2021 SB2021072901
SB2021072902
SB2021081231
and 14 more
#VU51012 - Deserialization of Untrusted Data
CVE-2021-25329
CWE-502 Medium
No
No
7.0.108, 8.5.63, 9.0.43, 10.0.2 01.03.2021 SB2021030115
SB2021031620
SB2021040723
and 16 more
#VU49570 - Exposure of sensitive information to an unauthorized actor
CVE-2021-24122
CWE-200 Medium
No
No
7.0.107, 8.5.60, 9.0.40, 10.0.0-M10 14.01.2021 SB2021011807
SB2021072821
SB2022012734
and 5 more
#VU29723 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-13935
CWE-835 Medium
Public exploit available
No
7.0.105, 8.5.57, 9.0.37, 10.0.0-M7 14.07.2020 SB2020071406
SB2020072801
SB2020072921
and 14 more
#VU28158 - Deserialization of Untrusted Data
CVE-2020-9484
CWE-502 High
Public exploit available
No
7.0.104, 8.5.55, 9.0.35, 10.0.0-M5 21.05.2020 SB2020052124
SB2020052501
SB2020053102
and 47 more
#VU25807 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-1935
CWE-444 Medium
No
No
7.0.100, 8.5.51, 9.0.31 06.03.2020 SB2020022111
SB2020031401
SB2020031402
and 15 more
#VU25502 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-1938
CWE-22 High
Public exploit available
Exploited
7.0.100, 8.5.51, 9.0.31 21.02.2020 SB2020022111
SB2020031401
SB2020031402
and 31 more
#VU25002 - Session Fixation
CVE-2019-17563
CWE-384 Low
No
No
7.0.99, 8.5.50, 9.0.30 06.02.2020 SB2019121315
SB2020011492
SB2020011519
and 16 more
#VU25000 - Permissions, Privileges, and Access Controls
CVE-2019-12418
CWE-264 Low
No
No
7.0.99, 8.5.49, 9.0.29 06.02.2020 SB2019112222
SB2020011492
SB2020011519
and 4 more
#VU18638 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-0221
CWE-79 Low
Public exploit available
No
7.0.94, 8.5.40, 9.0.19 30.05.2019 SB2019041101
SB2019070106
SB2019072501
and 13 more
#VU18236 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2019-0232
CWE-78 High
Public exploit available
Exploited
7.0.94, 8.5.40, 9.0.19 11.04.2019 SB2019041101
SB2019052003
SB2020012015
and 5 more
#VU15156 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2018-11784
CWE-601 Low
Public exploit available
No
7.0.91, 8.5.34, 9.0.12 05.10.2018 SB2018100401
SB2018102605
SB2018110806
and 13 more
#VU13992 - Permissions, Privileges, and Access Controls
CVE-2018-8034
CWE-264 Low
No
No
7.0.90, 9.0.10 25.06.2018 SB2018072404
SB2018081002
SB2018081005
and 13 more
#VU13986 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2018-1336
CWE-835 Medium
No
No
7.0.88, 8.0.52, 8.5.31, 9.0.8 16.05.2018 SB2018051612
SB2018080607
SB2018080608
and 12 more
#VU10707 - Permissions, Privileges, and Access Controls
CVE-2018-1304
CWE-264 Low
No
No
7.0.85, 8.0.50, 8.5.28, 9.0.5 26.02.2018 SB2018022601
SB2018032308
SB2018032107
and 11 more
#VU10706 - Permissions, Privileges, and Access Controls
CVE-2018-1305
CWE-264 Low
No
No
- 26.02.2018 SB2018022601
SB2018032308
SB2018032107
and 8 more
#VU8669 - Improper input validation
CVE-2017-12617
CWE-20 High
Public exploit available
Exploited
- 04.10.2017 SB2017100401
SB2017102604
SB2017112403
and 20 more
#VU8543 - Exposure of sensitive information to an unauthorized actor
CVE-2017-12616
CWE-200 Low
No
No
- 21.09.2017 SB2017092101
SB2017092116
SB2017112404
and 2 more
#VU8541 - Improper input validation
CVE-2017-12615
CWE-20 High
Public exploit available
Exploited
- 21.09.2017 SB2017092101
SB2017112404
SB2018020603
and 10 more
#VU6675 - Improper Access Control
CVE-2017-5648
CWE-284 Low
No
No
- 24.05.2017 SB2017052404
SB2017111701
SB2017111702
and 10 more


Showing elements 1 - 20 out of 32