Known vulnerabilities in Apache Tomcat 8.5.45 - page 2

Software: Apache Tomcat
Version: 8.5.45
Software CPE: cpe:2.3:a:apache_foundation:apache_tomcat:*:*:*:*:*:*:*:*
Total vulnerabilities: 35
Public exploits: 11
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Apache Tomcat version 8.5.45 Apache Tomcat 8.5.45 is affected by 35 vulnerabilities: 3 high, 26 medium, 6 low Critical High Medium Low

Vulnerabilities (35)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU55422 - Improper Handling of Exceptional Conditions
CVE-2021-30639
CWE-755 Medium
No
No
8.5.65, 9.0.45, 10.0.5 29.07.2021 SB2021072906
SB2021072908
SB2022011825
and 6 more
#VU55417 - Improper Authentication
CVE-2021-30640
CWE-287 Medium
No
No
7.0.109, 8.5.66, 9.0.46, 10.0.6 29.07.2021 SB2021072901
SB2021072902
SB2021081231
and 14 more
#VU51014 - Resource Management Errors
CVE-2021-25122
CWE-399 Medium
No
No
8.5.63, 9.0.43, 10.0.2 01.03.2021 SB2021030115
SB2021031619
SB2021032519
and 23 more
#VU51012 - Deserialization of Untrusted Data
CVE-2021-25329
CWE-502 Medium
No
No
7.0.108, 8.5.63, 9.0.43, 10.0.2 01.03.2021 SB2021030115
SB2021031620
SB2021040723
and 16 more
#VU49570 - Exposure of sensitive information to an unauthorized actor
CVE-2021-24122
CWE-200 Medium
No
No
7.0.107, 8.5.60, 9.0.40, 10.0.0-M10 14.01.2021 SB2021011807
SB2021072821
SB2022012734
and 5 more
#VU48779 - Resource Management Errors
CVE-2020-17527
CWE-399 Medium
No
No
8.5.60, 9.0.40, 10.0.0-M10 03.12.2020 SB2020120401
SB2020120509
SB2020120510
and 21 more
#VU47516 - Resource Management Errors
CVE-2020-13943
CWE-399 Medium
No
No
8.5.58, 9.0.38, 10.0.0-M8 12.10.2020 SB2020101213
SB2020110102
SB2020110603
and 6 more
#VU29724 - Resource Management Errors
CVE-2020-13934
CWE-399 Medium
No
No
8.5.57, 9.0.37, 10.0.0-M7 14.07.2020 SB2020071406
SB2020072801
SB2020072921
and 5 more
#VU29723 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-13935
CWE-835 Medium
Public exploit available
No
7.0.105, 8.5.57, 9.0.37, 10.0.0-M7 14.07.2020 SB2020071406
SB2020072801
SB2020072921
and 14 more
#VU29333 - Resource Management Errors
CVE-2020-11996
CWE-399 Medium
Public exploit available
No
8.5.56, 9.0.36, 10.0.0-M6 27.06.2020 SB2020062701
SB2020062802
SB2020072414
and 6 more
#VU28158 - Deserialization of Untrusted Data
CVE-2020-9484
CWE-502 High
Public exploit available
No
7.0.104, 8.5.55, 9.0.35, 10.0.0-M5 21.05.2020 SB2020052124
SB2020052501
SB2020053102
and 47 more
#VU25807 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-1935
CWE-444 Medium
No
No
7.0.100, 8.5.51, 9.0.31 06.03.2020 SB2020022111
SB2020031401
SB2020031402
and 15 more
#VU25502 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-1938
CWE-22 High
Public exploit available
Exploited
7.0.100, 8.5.51, 9.0.31 21.02.2020 SB2020022111
SB2020031401
SB2020031402
and 31 more
#VU25002 - Session Fixation
CVE-2019-17563
CWE-384 Low
No
No
7.0.99, 8.5.50, 9.0.30 06.02.2020 SB2019121315
SB2020011492
SB2020011519
and 16 more
#VU25000 - Permissions, Privileges, and Access Controls
CVE-2019-12418
CWE-264 Low
No
No
7.0.99, 8.5.49, 9.0.29 06.02.2020 SB2019112222
SB2020011492
SB2020011519
and 4 more


Showing elements 21 - 40 out of 35